Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.
CVE ID: CVE-2025-1985
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vendor: Pepperl+Fuchs
Product: Profinet Gateway FB8122A.1.EL, Profinet Gateway LB8122A.1.EL
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 12.77% (scored less or equal to compared to others)
EPSS Date: 2025-06-18 (when was this score calculated)