CVE-2025-52609: HCL iControl was affected by Missing Security Headers vulnerability.
Published Jun 4, 2026
·Updated
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
Affected Software
2 affected components
HCL iControl
hcltech Icontrol=4.0.0
Event History
Jun 4, 2026
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52609?
The severity of CVE-2025-52609 is low, rated at 3.7.
2
How do I fix CVE-2025-52609?
To fix CVE-2025-52609, ensure that all necessary security headers are implemented in HCL iControl.
3
What type of vulnerability is CVE-2025-52609?
CVE-2025-52609 is classified as a Missing Security Headers vulnerability which can lead to cross-site scripting attacks.
4
What is the impact of CVE-2025-52609?
CVE-2025-52609 can lead to cross-site scripting (XSS) attacks by exploiting the absence of security headers.
5
Who is affected by CVE-2025-52609?
Users of HCL iControl are affected by CVE-2025-52609 due to the missing security headers in the application.