CVE-2025-3020 - CVE House
Back to Database
Status published Medium CVE-2025-3020

Wiesemann & Theis: Multiple W&T Products are vulnerable to cross-site-scripting

Vulnerability Description

An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with limited impact.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3020

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Wiesemann & Theis

View all reports →

Affected Software

ERP-Gateway 12x Digital Input, 6x Digital Relais, ERP-Gateway 2x Digital Input, 2x Digital Output, ERP-Gateway 2x Digital PoE, Web-Alarm 6x6 DigitalWeb-Alarm 6x6 Digital, Web-Count 6x Digital, Web-Graph Air Quality, Web-IO 12x Digital Input, 6x Digital Relais, Web-IO Analog-In/Out 2x 0/4..20mA PoE, Web-IO Digital 12xIn, 12xOut, Web-IO Digital 12xIn, 12xOut, 1xRS232, Web-IO Digital 2xIn, 2xOut, Web-IO Digital Logger 6xIn, 6xOut, Web-Thermograph 2x, Web-Thermograph 8x, Web-Thermograph NTC, Web-Thermograph NTC PoE, Web-Thermograph Pt100 / Pt1000, Web-Thermograph Pt100 / Pt1000 PoE, Web-Thermograph Relais, Web-Thermo-Hygrobarograph, Web-Thermo-Hygrograph
Vulnerable Versions:
all, 0

Timeline

Official Publish: May 6th, 2025
Last Modified: May 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Weaknesses (CWE)