Executive brief
The Location Aware Sensor System (LASS) for Linkit ONE is susceptible to a security flaw where attackers can run unauthorized code in a user's web browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal session information or perform actions on the user's behalf within the application. This affects systems using the software version released on or before April 26, 2023.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the PM25.php file of the Linkit ONE Location Aware Sensor System (LASS). The vulnerability stems from improper neutralization of user-supplied input in several GET parameters, including 'site', 'city', 'district', 'channel', and 'apikey'. A remote, unauthenticated attacker can exploit this by persuading a victim to visit a malicious URL containing unencoded JavaScript payloads. Successful exploitation allows the execution of arbitrary script code in the context of the victim's browser session. The issue affects all versions up to and including Git commit f06bd20.
Affected products
- LinkItONEDevGroup Location Aware Sensor System (LASS) up to commit f06bd20 (2023-04-26)
Timeline
- 2026-03-19: advisory: Initial advisory published by VulnCheck
- 2026-03-19: disclosed: CVE-2026-32843 published