Medium severity6.1NVD Advisory· Published Sep 2, 2025· Updated Jun 17, 2026
CVE-2025-52546
CVE-2025-52546
Description
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page.
Affected products
2- cpe:2.3:o:copeland:e3_supervisory_controller_firmware:*:*:*:*:*:*:*:*Range: <2.31f01
- Copeland LP/E3 Supervisory Controlv5Range: 0
Patches
Vulnerability mechanics
References
1- www.armis.com/research/frostbyte10/nvdMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.