CVE-2025-26389
A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDiagramPage` endpoint. This could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
Vendor
Product
CWE
Yayın Tarihi
2025-05-13 10:15:23
Güncelleme
2025-10-06 10:34:26
Source Identifier
productcert@siemens.com
KEV Date Added
-