216.73.217.22

CVE-2025-6185

· Published 18/07/2025 00:15 · Modified 18/07/2025 00:15

Labels: CVE-2025-6185 2025-07-18CVE-2025-6185CWE-79[email protected]

Essential information

Published
18/07/2025 00:15
Modified
18/07/2025 00:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
leviton / acquisuite cpe:2.3:a:leviton:acquisuite:*:*:*:*:*:*:*:*
leviton / energy monitoring hub cpe:2.3:a:leviton:energy_monitoring_hub:*:*:*:*:*:*:*:*

References