Junglewise Threat Intelligence

CVE-2026-12622: Microchip GridTime 3000 open redirect in password change form

CVE-2026-12622 · Severity: info · CVSS 5.3 · Published 2026-06-19

Technologies: Microchip Technology GridTime 3000 GNSS Time Server. Vendors: Microchip Technology.

Executive brief

The Microchip GridTime 3000, a high-precision time server used in critical infrastructure, contains a security flaw in its password change interface. This vulnerability allows attackers to redirect users to malicious external websites, which could be used in phishing campaigns to steal credentials or deliver malware. While it does not directly grant access to the device, it compromises the trust and security of the administrative session.

Technical details

An open redirect vulnerability (CWE-601) exists in the Microchip GridTime 3000 GNSS Time Server within the password change form submission component. The application fails to properly validate or sanitize the destination URL after a password change action, allowing a remote attacker with low privileges to redirect users to arbitrary external domains. This is typically exploited by crafting a malicious link that appears to be a legitimate administrative action but sends the victim to an attacker-controlled site upon completion. The vulnerability affects versions 1.0r0.03 through 1.1r0.0.

Affected products

  • Microchip Technology GridTime 3000 GNSS Time Server 1.0r0.03 through 1.1r0.0

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory

References

Related threats