nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-24344 CVE-2025-24344
MEDIUM
Record summary
CVE-2025-24344 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the context of another user's browser via a crafted HTTP request.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ctrlX OS - SolutionsBrowse Bosch Rexroth AG / ctrlX OS - Solutions | CVE List | 1.12.0 to ≤ 1.12.1 | affected |
| 1.20.0 to ≤ 1.20.1 | affected | ||
| 2.6.0 to ≤ 2.6.0 | affected |
References
2psirt.bosch.comVendor advisory
https://psirt.bosch.com/security-advisories/BOSCH-SA-640452.html