CVE-2025-6185
Leviton AcquiSuite and Energy Monitoring Hub
are susceptible to a cross-site scripting vulnerability, allowing
an attacker to craft a malicious payload in URL parameters, which would
execute in a client browser when accessed by a user, steal session
tokens, and control the service.
Assigner : ics-cert@hq.dhs.gov
More information : https://leviton.com/support/resources/product-support