CVE-2025-6185

Severity CVSS v4.0:
HIGH
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/07/2025
Last modified:
22/07/2025

Description

Leviton AcquiSuite and Energy Monitoring Hub <br /> are susceptible to a cross-site scripting vulnerability, allowing <br /> an attacker to craft a malicious payload in URL parameters, which would <br /> execute in a client browser when accessed by a user, steal session <br /> tokens, and control the service.