Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-3020
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wiesemann & Theis: Multiple W&T Products are vulnerable to cross-site-scripting
Source: NVD (National Vulnerability Database)
Vulnerability Description
An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with limited impact.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Wiesemann & Theis Web-IO 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Wiesemann & Theis Web-IO是Wiesemann & Theis公司的一个用于通过 TCP/IP 以太网实现中小型远程 IO和监控应用程序的组件。 Wiesemann & Theis Web-IO存在跨站脚本漏洞,该漏洞源于配置网页中多个字段可注入特制有效载荷,可能导致执行任意Web脚本或HTML。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Wiesemann & TheisERP-Gateway 12x Digital Input, 6x Digital Relais all -
Wiesemann & TheisERP-Gateway 2x Digital Input, 2x Digital Output all -
Wiesemann & TheisERP-Gateway 2x Digital PoE all -
Wiesemann & TheisWeb-Alarm 6x6 DigitalWeb-Alarm 6x6 Digital all -
Wiesemann & TheisWeb-Count 6x Digital 0 ~ 3.79 -
Wiesemann & TheisWeb-Graph Air Quality all -
Wiesemann & TheisWeb-IO 12x Digital Input, 6x Digital Relais all -
Wiesemann & TheisWeb-IO 12x Digital Input, 6x Digital Relais all -
Wiesemann & TheisWeb-IO 12x Digital Input, 6x Digital Relais all -
Wiesemann & TheisWeb-IO Analog-In/Out 2x 0/4..20mA PoE all -
Wiesemann & TheisWeb-IO Digital 12xIn, 12xOut all -
Wiesemann & TheisWeb-IO Digital 12xIn, 12xOut all -
Wiesemann & TheisWeb-IO Digital 12xIn, 12xOut 0 ~ 4.08 -
Wiesemann & TheisWeb-IO Digital 12xIn, 12xOut, 1xRS232 all -
Wiesemann & TheisWeb-IO Digital 12xIn, 12xOut, 1xRS232 all -
Wiesemann & TheisWeb-IO Digital 2xIn, 2xOut all -
Wiesemann & TheisWeb-IO Digital 2xIn, 2xOut all -
Wiesemann & TheisWeb-IO Digital 2xIn, 2xOut all -
Wiesemann & TheisWeb-IO Digital Logger 6xIn, 6xOut 0 ~ 3.70 -
Wiesemann & TheisWeb-Thermograph 2x all -
Wiesemann & TheisWeb-Thermograph 8x all -
Wiesemann & TheisWeb-Thermograph NTC all -
Wiesemann & TheisWeb-Thermograph NTC PoE all -
Wiesemann & TheisWeb-Thermograph Pt100 / Pt1000 all -
Wiesemann & TheisWeb-Thermograph Pt100 / Pt1000 PoE all -
Wiesemann & TheisWeb-Thermograph Relais all -
Wiesemann & TheisWeb-Thermo-Hygrobarograph all -
Wiesemann & TheisWeb-Thermo-Hygrograph all -
II. Public POCs for CVE-2025-3020
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-3020
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-3020

No comments yet


Leave a comment