CVE-2025-9139 Information
Description
A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information disclosure. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor explains: [T]he risks of indicated vulnerabilities seem to be minimal as all scenarios likely require admin permissions. Moreover regardless our team fixes those vulnerabilities - the overall risk change to the user due to malicious admin actions will not be lower.\
Reference
https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/Sensitive%20User%20Information%20Disclosure%20via%20WatchListDwr.init.dwr%20Endpoint.md#proof-of-concept-poc https://vuldb.com/?ctiid.320519 https://vuldb.com/?id.320519 https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/Sensitive%20User%20Information%20Disclosure%20via%20WatchListDwr.init.dwr%20Endpoint.md https://vuldb.com/?submit.621062 https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/Sensitive%20User%20Information%20Disclosure%20via%20WatchListDwr.init.dwr%20Endpoint.md#proof-of-concept-poc https://vuldb.com/?submit.621062
Related CNNVD
CNNVD-202508-2089 (Published: 2025-08-19)
Share on: