Junglewise Threat Intelligence

CVE-2026-30695: Zucchetti Axess XSS in file_manager.cgi

CVE-2026-30695 · Severity: medium · CVSS 6.1 · Published 2026-03-18

Executive brief

Zucchetti Axess access control devices, which are used to manage physical security and building entry, contain a security flaw in their web management interface. An attacker can trick a legitimate user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions, unauthorized changes to security settings, or the exposure of sensitive device information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /file_manager.cgi endpoint of Zucchetti Axess access control devices. The root cause is the improper sanitization of the 'dirBrowse' GET parameter, which allows an attacker to inject arbitrary JavaScript into the web interface. While the attack requires a victim to interact with a malicious link (User Interaction), it can be executed remotely over the network without prior authentication. Successful exploitation allows for session hijacking, privilege escalation, and unauthorized configuration changes by executing code within the context of an administrative user's session. Affected models include XA4, X3, X4, X7, and XIO series running various firmware builds such as h06 build 5522.

Affected products

  • Zucchetti Axess XA4 h06 build 5522
  • Zucchetti Axess X3/X3BIO h02 build 4163
  • Zucchetti Axess X4 All versions
  • Zucchetti Axess X7 All versions
  • Zucchetti Axess XIO / i-door / i-door+ h06 build 5522

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: advisory

References