CVE-2025-13649 Details
Description
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Email’ parameters within the ‘Recover password’ section at the URL: https://zeus.microcom.es:4040/index.html?zeus6=true . This issue affects ZeusWeb: 6.1.31.
A stored cross-site scripting vulnerability has been identified in the ZeusWeb application by Microcom, specifically in version 6.1.31. This issue allows an attacker to inject arbitrary JavaScript by placing an XSS payload in the 'Email' parameters within the 'Recover Password' section. The vulnerability is present in the web application accessible at 'https://zeus.microcom.es:4040/index.html?zeus6=true'.
Users of ZeusWeb do not need to take any action, as the application is cloud-based and the provider has automatically updated all users to version 6.2.5, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hackrtu.com/blog/CNA-CVE-2025-13649/ | HackRTU | Third Party Advisory |
| https://www.hackrtu.com/blog/CNA-HRTU-0001/ | HackRTU | Third Party Advisory |
| https://www.microcom360.com/servicio-zeus-web/ | HackRTU | Product |
| https://zeus.microcom.es:4040/ | HackRTU | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | HackRTU |
Affected Products
| Product | Versions |
|---|---|
| microcom360 zeusweb | 6.1.31 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | HackRTU |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Feb 11, 2026 | New CVE Received | HackRTU |