Hitachi Energy LinkOne WebView
LinkOne WebView versions 3.20 through 3.26 contain multiple web-based vulnerabilities: cross-site scripting (CWE-79) allowing injection of malicious code, information disclosure flaws (CWE-200, CWE-209) that expose application paths and sensitive data, and improper handling of cross-origin requests (CWE-693). An authenticated attacker could modify system files, extract credentials or configuration data, and launch web-based attacks. High attack complexity limits real-world exploitation. No known public exploits exist.
- Valid user credentials for LinkOne WebView
- Network access to LinkOne WebView web interface (HTTP/HTTPS)
- Knowledge of application endpoints (attacker can enumerate via CWE-209 disclosures)
- High attack complexity required (per CVSS rating)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/718836f4-eb30-4382-a677-c3c54964059aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.