CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-62172: core >= 2025.1.0, < 2025.10.2

CVE-2025-62172. EPSS 0.00422 (percentile 0.34397), scored 2026-10-06.

Affected technology

core · >= 2025.1.0, < 2025.10.2
home-assistant

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · Active user interaction

What an attacker can do

An authenticated user can inject malicious JavaScript code into an energy entity's name field, which is then executed when any user hovers over data points in the energy dashboard graph tooltips. Vendor/CNA’s CVSS 4.0 assessment (base score 8.5/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-79, CWE-80
CCR priority
0.1 /100 (P5)
EPSS
0.00422 · percentile 0.34506 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-62172.html