Executive brief
A vulnerability exists in the Teldat Regesta Smart HD-PLC, an industrial router used for power-line communications. An attacker with administrative access can inject malicious scripts into the device's configuration file. If a legitimate user views the affected management page, the script could execute, potentially allowing the attacker to perform unauthorized actions or steal session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Teldat Regesta Smart HD-PLC (TLDPH16D2) firmware version 11.02.05.10.02. The vulnerability is located in the 'Hostname' field of the device configuration file. An authenticated attacker with high privileges (PR:H) can inject a malicious JavaScript payload into this field. When the configuration is processed, the payload is executed in the context of the user's browser at the path /upgrade/query.php?cmd=p+3%3Bversion. This allows for arbitrary code execution in the client-side session. The issue is resolved in firmware version 11.02.06.00.02.
Affected products
- Teldat Regesta Smart HD-PLC - TLDPH16D2 11.02.05.10.02
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched: Fixed in version 11.02.06.00.02
References
- https://support.teldat.com/images/content/docs/Teldat_dm1087_regesta_smart_nessum_series_installation(1).pdf
- https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US
- https://www.hackrtu.com/blog/CNA-CVE-2026-27870/
- https://www.hackrtu.com/blog/CNA-HRTU-0002/
- https://www.teldat.com/es/