Executive brief
Siemens SIMATIC S7 PLCs, which are industrial controllers used to automate factory processes and infrastructure, contain a security vulnerability in their web management interface. An attacker with the ability to download projects to the controller can inject malicious scripts that execute when an administrator views the device's communication settings. This could lead to the theft of administrative session credentials, unauthorized changes to device configurations, or a complete takeover of the web-based management session.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the web server of multiple Siemens SIMATIC S7 PLC families. The flaw is located in the 'communication' parameters page, which fails to properly validate and sanitize PLC/station names rendered in the UI. An authenticated attacker with privileges to download a TIA project to the device can inject malicious scripts into these fields. When a user with higher privileges (such as an administrator) accesses the affected page, the script executes within their browser session. This can lead to session hijacking, unauthorized configuration changes, or further exploitation of the administrative interface. Siemens has released firmware updates for several models (e.g., V3.1.6, V2.9.9, V4.1.6) to address this issue.
Affected products
- Siemens SIMATIC Drive Controller CPU 1504D TF < V3.1.6
- Siemens SIMATIC Drive Controller CPU 1507D TF < V3.1.6
- Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 All versions affected
- Siemens SIMATIC ET 200SP CPU 1510SP F-1 PN < V2.9.9, < V4.1.6
- Siemens SIMATIC S7-1500 CPU 1511-1 PN < V2.9.9, < V4.1.6
CVE identifiers
- CVE-2026-25789
- CVE-2026-25787
- CVE-2026-25786
Timeline
- 2026-05-12: advisory: Initial publication of SSA-688146
- 2026-07-14: patched: Advisory updated with additional fix information