PT-2026-25783 · Shenzhen Hereta Technology Co. · Hereta Eth-Imc408M
Kazuma Matsumoto
·
Published
2026-03-16
·
Updated
2026-03-17
·
CVE-2026-29520
CVSS v3.1
6.1
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping ipaddr parameter to compromise authenticated administrator sessions when the links are visited.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hereta Eth-Imc408M