CVE-2026-12948: Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12948?
CVE-2026-12948 has a medium severity rating with a CVSS score of 4.8.
How do I fix CVE-2026-12948?
To fix CVE-2026-12948, ensure that you update the affected Digi devices to the latest firmware version provided by Digi.
What systems are affected by CVE-2026-12948?
CVE-2026-12948 affects the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices.
What type of vulnerability is CVE-2026-12948?
CVE-2026-12948 is classified as a stored cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2026-12948?
CVE-2026-12948 can be exploited by a remote, authenticated administrator.