PT-2026-35168 · Bdcom · P3310D

Havook

·

Published

2026-04-25

·

Updated

2026-04-25

·

CVE-2026-6995

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions BDCOM P3310D version 0.4.2 10.1.0F Build 86345
Description A security flaw in the New User Page component allows remote attackers to perform cross-site scripting (XSS), which is a technique where malicious scripts are injected into trusted websites. The issue exists within an unknown function of the '/index.asp' endpoint, specifically through the manipulation of the User name argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6995

Affected Products

P3310D