CVE-2026-22913: XSS
Published Jan 15, 2026
·Updated
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.
Affected Software
2 affected components
All of the following
SICK Tdc-x401gl Firmware<1.5.0
SICK Tdc-x401gl
Remediation
Information
Users are strongly recommended to upgrade to the latest release of TDC-X401GL (>= 1.5.0).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 20, 58071
Event
via FIRST·04:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-22913?
CVE-2026-22913 is considered a high severity vulnerability due to its potential to allow code execution in a user's browser.
2
How do I fix CVE-2026-22913?
To fix CVE-2026-22913, ensure that the affected firmware is updated to the latest version beyond 1.5.0.
3
What impact can CVE-2026-22913 have on sensitive data?
CVE-2026-22913 can lead to the extraction of sensitive data if an attacker successfully exploits the vulnerability.
4
Who is affected by CVE-2026-22913?
CVE-2026-22913 affects users of the SICK Tdc-x401gl Firmware version 1.5.0 and earlier.
5
What type of attack is associated with CVE-2026-22913?
CVE-2026-22913 is associated with a URL parameter manipulation attack that can lead to cross-site scripting.