Junglewise Threat Intelligence

CVE-2026-12352: Digi International PortServer and Digi One authentication bypass

CVE-2026-12352 · Severity: medium · CVSS 5.9 · Published 2026-07-07

Executive brief

Digi International serial-to-Ethernet connectivity devices, used to connect legacy industrial equipment to modern networks, contain a security flaw that allows unauthorized users to bypass login requirements. An attacker could exploit this to access restricted device resources and sensitive information without needing a password. This could lead to unauthorized monitoring of industrial communications or changes to device configurations.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the firmware of several Digi International terminal server products, including PortServer TS and Digi One series. The flaw allows an unauthenticated actor to bypass authentication mechanisms and gain access to restricted resources on the device. The attack vector is network-based, though the CVSS assessment indicates high complexity (AC:H), likely requiring specific timing or environmental conditions to successfully bypass the check. Digi has identified mitigations and firmware updates to address the issue for affected devices running firmware released in 2025 or earlier.

Affected products

  • Digi International PortServer TS 1/2/4 82000747_V1 through 82000747_AB
  • Digi International Digi One SP / SP IA / IA 82000774-W through 93000459_AB
  • Digi International Digi One IAP All firmware released in 2025 or earlier

Timeline

  • 2026-07-07: advisory: Initial advisory published by Digi and NVD record created.
  • 2026-07-07: patched: Digi confirmed mitigations and fixes were developed.

References

Related threats