Junglewise Threat Intelligence

CVE-2026-12948: Digi PortServer and Digi One stored XSS in web management interface

CVE-2026-12948 · Severity: info · CVSS 4.8 · Published 2026-07-07

Executive brief

A security vulnerability exists in the web management interface of several Digi device servers, including the PortServer TS and Digi One series. These devices are used to connect serial equipment to networks. An attacker with administrative privileges could inject malicious scripts into the device configuration, which would then execute in the browser of other users who view those settings, potentially leading to unauthorized actions or data theft within the management session.

Technical details

A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in the web management interface of Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA. The flaw is located in certain system configuration fields that do not properly neutralize user-supplied input. An authenticated attacker with high privileges (administrator) can inject malicious JavaScript into these fields. The script is then executed in the context of any user (typically another administrator) who subsequently views the affected configuration pages. This could allow for session hijacking or unauthorized configuration changes. The vulnerability affects firmware versions 82000747_V1 through 82000747_AB.

Affected products

  • Digi International PortServer TS 82000747_V1 through 82000747_AB
  • Digi International Digi One SP 82000747_V1 through 82000747_AB
  • Digi International Digi One SP IA 82000747_V1 through 82000747_AB
  • Digi International Digi One IA 82000747_V1 through 82000747_AB

Timeline

  • 2026-07-07: disclosed: Initial publication of the vulnerability advisory.
  • 2026-07-07: advisory: Digi International released a security advisory regarding the XSS vulnerability.

References

Related threats