CVE-2025-41768

Publication date

2026-01-20 08:02:53

Family

CERTVDE

State

PUBLISHED

Description

On an instance of TwinCAT 3 HMI Server running on a device an authenticated administrator can inject arbitrary content into the custom CSS field which is persisted on the device and later returned via the login page and error page.