Executive brief
The Microchip GridTime 3000, a high-precision time server used in critical infrastructure, contains a security flaw in its password change interface. This vulnerability allows attackers to redirect users to malicious external websites, which could be used in phishing campaigns to steal credentials or deliver malware. While it does not directly grant access to the device, it compromises the trust and security of the administrative session.
Technical details
An open redirect vulnerability (CWE-601) exists in the Microchip GridTime 3000 GNSS Time Server within the password change form submission component. The application fails to properly validate or sanitize the destination URL after a password change action, allowing a remote attacker with low privileges to redirect users to arbitrary external domains. This is typically exploited by crafting a malicious link that appears to be a legitimate administrative action but sends the victim to an attacker-controlled site upon completion. The vulnerability affects versions 1.0r0.03 through 1.1r0.0.
Affected products
- Microchip Technology GridTime 3000 GNSS Time Server 1.0r0.03 through 1.1r0.0
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory