CVE-2026-22919: XSS
Published Jan 15, 2026
·Updated
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
Affected Software
2 affected components
All of the following
SICK Tdc-x401gl Firmware<1.5.0
SICK Tdc-x401gl
Remediation
Information
Users are strongly recommended to upgrade to the latest release of TDC-X401GL (>= 1.5.0).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 20, 58071
Event
via FIRST·10:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-22919?
CVE-2026-22919 is considered a critical vulnerability due to its potential for enabling cross-site scripting (XSS) attacks.
2
How do I fix CVE-2026-22919?
To fix CVE-2026-22919, ensure that the firmware is updated to a version greater than 1.5.0.
3
What causes CVE-2026-22919?
CVE-2026-22919 is caused by an attacker with administrative access injecting malicious content into the login page.
4
What are the potential impacts of CVE-2026-22919?
The potential impacts of CVE-2026-22919 include the extraction of sensitive data through successful XSS attacks.
5
Is my system vulnerable to CVE-2026-22919?
Your system is vulnerable to CVE-2026-22919 if you are using SICK Tdc-x401gl Firmware version 1.5.0 or lower.