SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12948

MEDIUM · CVSS 4.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

A stored cross-site scripting (XSS) vulnerability exists in the web management interface of several Digi products, allowing a remote, authenticated administrator to inject malicious scripts into system configuration fields. This could lead to the execution of the injected script in the browsers of users accessing the affected pages, potentially compromising user data and session integrity. Organizations using these Digi devices, particularly those with remote administrative access, should prioritize addressing this vulnerability to mitigate risks associated with unauthorized script execution.

CVE
CVE-2026-12948
Severity
MEDIUM
CVSS
4.8
EPSS
0.27%

Original NVD Description

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).