CVE-2025-13648 Details
Description
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is required) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Name’ and “Surname” parameters within the ‘My Account’ section at the URL: https://zeus.microcom.es:4040/administracion-estaciones.html resulting in a stored XSS. This issue affects ZeusWeb: 6.1.31.
A stored cross-site scripting vulnerability has been identified in the ZeusWeb application by Microcom, specifically in version 6.1.31. This issue allows an attacker with access to the web application to inject arbitrary JavaScript. The vulnerability arises from injecting an XSS payload into the 'Name' and 'Surname' parameters within the 'My Account' section, on the 'administracion-estaciones.html' page.
Users of Microcom's ZeusWeb do not need to take any action, as the software is cloud-based and the provider has automatically updated all users to version 6.2.5, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hackrtu.com/blog/CNA-CVE-2025-13648/ | HackRTU | Third Party Advisory |
| https://www.hackrtu.com/blog/CNA-HRTU-0001/ | HackRTU | Third Party Advisory |
| https://www.microcom360.com/servicio-zeus-web/ | HackRTU | Product |
| https://zeus.microcom.es:4040/ | HackRTU | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | HackRTU |
Affected Products
| Product | Versions |
|---|---|
| microcom360 zeusweb | 6.1.31 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | HackRTU |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Feb 11, 2026 | New CVE Received | HackRTU |