Junglewise Threat Intelligence

CVE-2026-25787: Siemens SIMATIC S7 PLCs XSS in Motion Control Diagnostics

CVE-2026-25787 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Technologies: Siemens SIMATIC Drive Controller CPU 1504D TF, Siemens SIMATIC Drive Controller CPU 1507D TF, Siemens SIMATIC S7-1500 CPU family, Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2. Vendors: Siemens.

Executive brief

Siemens SIMATIC S7-1500 and related industrial controllers contain a security vulnerability in their built-in web management interface. An attacker with the ability to download projects to the controller can inject malicious code that executes when an administrator views the diagnostics page. This could lead to the theft of administrative session credentials or unauthorized control over the device's web-based management functions.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the web server of multiple Siemens SIMATIC S7 PLC families, including S7-1500 and ET 200SP. The vulnerability is caused by improper validation and sanitization of Technology Object (TO) names rendered on the 'Motion Control Diagnostics' page. An authenticated attacker with privileges to download a TIA project to the PLC can use a specially crafted TO name to inject malicious scripts. When a legitimate user with appropriate rights accesses the affected diagnostics page, the script executes within their browser session. This can result in a full compromise of the user's web session, potentially allowing the attacker to perform administrative actions or escalate privileges. Siemens has released firmware updates for several product lines to address this issue.

Affected products

  • Siemens SIMATIC S7-1500 CPU family All versions < V2.9.9 or < V4.1.6 (depending on model)
  • Siemens SIMATIC Drive Controller family All versions < V3.1.6
  • Siemens SIMATIC ET 200SP CPU family All versions < V2.9.9 or < V4.1.6 (depending on model)
  • Siemens SIMATIC ET 200SP Open Controller All versions

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-07-14: other: Advisory updated by Siemens

References

Related threats