Description
Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.
Problem types
Product status
Any version
Credits
Alex Williams of Pellera Technologies reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-310-01
github.com/...p/csaf_files/OT/white/2025/icsa-25-310-01.json