VDB
CVE-2025-26389
CVE-2025-26389
PUBLISHED
CVSS 10 CRITICAL
A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDiagramPage` endpoint. This could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
EPSS 0.95% · 59.2th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.95%
59.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| siemens | ozw772_firmware | 0 |
| siemens | ozw672_firmware | 0 |
| Siemens | OZW772 | 0 |
| Siemens | OZW672 | 0 |
Timeline
- Feb 7, 2025 CVE ID Reserved
- May 13, 2025 EPSS Score
- May 13, 2025 CVE Published
- May 13, 2025 CVE Updated
- May 15, 2025 PoC Published
- May 25, 2025 EPSS Score
- May 31, 2025 Coalition ESS Score
- Jun 6, 2025 EPSS Score
- Jun 17, 2025 EPSS Score
- Jun 29, 2025 EPSS Score
- Jul 11, 2025 EPSS Score
- Jul 23, 2025 EPSS Score