CVE-2026-97871: Zhonglun CloudPos JSBridge JSBridge.cs OpenLocalBrowser code injection
A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Zhonglun CloudPos versions up to and including 3.0.1.76 are identified as affected. The issue is in the JSBridge component's OpenLocalBrowser function in ZlPos/ZlPos/Bizlogic/JSBridge.cs.
Does exploitation require authentication or user interaction?
The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. The vulnerability can be exploited remotely through manipulation of the url argument.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used. The reported exploit maturity is proof-of-concept.
Is a vendor fix or workaround available?
The provided information does not identify a vendor fix or workaround. It states that the vendor was contacted early about the disclosure but did not respond.