PT-2026-44969 · Cp Plus · Cp-Unr-108F1 Hardware+2

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-6824

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or users access affected pages, the stored scripts are executed in their browsers, leading to potential session hijacking, unauthorized actions, or data theft.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6824

Affected Products

Cp-Unr-108F1 Hardware
Cp-Unr-108F1 System
Cp-Unr-108F1 Web