PT-2026-25783 · Shenzhen Hereta Technology Co. · Hereta Eth-Imc408M

Kazuma Matsumoto

·

Published

2026-03-16

·

Updated

2026-03-17

·

CVE-2026-29520

CVSS v3.1
6.1
VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping ipaddr parameter to compromise authenticated administrator sessions when the links are visited.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-29520

Affected Products

Hereta Eth-Imc408M