CVE-2025-13902: XSS
Published Mar 10, 2026
·Updated
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.
Affected Software
8 affected components
All of the following
Schneider-electric Modicon M258 Firmware
Schneider-electric Modicon M258
All of the following
Schneider-electric Modicon Lmc058 Firmware
Schneider-electric Modicon Lmc058
All of the following
Schneider-electric Modicon M251 Firmware<5.4.13.12
Schneider-electric Modicon M251
All of the following
Schneider-electric Modicon M241 Firmware<5.4.13.12
Schneider-electric Modicon M241
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13902?
CVE-2025-13902 has a medium severity rating of 5.1.
2
What type of vulnerability is CVE-2025-13902?
CVE-2025-13902 is a Cross-site Scripting (XSS) vulnerability.
3
Who is affected by CVE-2025-13902?
CVE-2025-13902 affects Schneider Electric Modicon firmware versions including M258, Lmc058, M251, and M241.
4
How do I fix CVE-2025-13902?
A patch is available to fix CVE-2025-13902.
5
What can an attacker do with CVE-2025-13902?
An attacker can exploit CVE-2025-13902 to execute arbitrary JavaScript in a victim's browser when they hover over a crafted element.