PT-2026-25783 · Shenzhen Hereta Technology Co. · Hereta Eth-Imc408M
Kazuma Matsumoto
·
Published
2026-03-16
·
Updated
2026-03-17
·
CVE-2026-29520
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hereta ETH-IMC408M firmware versions prior to 1.0.15
Description
The software contains a reflected cross-site scripting issue in the Network Diagnosis ping function. This allows attackers to execute arbitrary JavaScript. Attackers can create malicious links with script payloads injected into the
ping ipaddr parameter. Successful exploitation can compromise authenticated administrator sessions when these links are visited.Recommendations
Update to a version prior to 1.0.15.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hereta Eth-Imc408M