PT-2026-3546 · Beckhoff Automation · Twincat 3 Hmi Server

Published

2026-01-20

·

Updated

2026-01-20

·

CVE-2025-41768

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TwinCAT 3 HMI Server (affected versions not specified)
Description An authenticated administrator can inject arbitrary content into the custom CSS field within TwinCAT 3 HMI Server. This injected content is saved on the device and subsequently returned through the login page and error page. The issue involves the ability to modify the visual presentation of these pages, potentially leading to phishing or other malicious activities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-41768

Affected Products

Twincat 3 Hmi Server