Junglewise Threat Intelligence

CVE-2026-52232: FS Inc S3150-8T2F Switch reflected XSS in logo.asp

CVE-2026-52232 · Severity: info · CVSS 6.1 · Published 2026-07-31

Executive brief

A security vulnerability exists in the web management interface of the FS S3150-8T2F network switch. By tricking an administrator into clicking a specially crafted link, an attacker can execute malicious scripts within the administrator's browser session. This could allow the attacker to hijack the management session, modify device configurations, or steal sensitive information like session cookies.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the /logo.asp page of the FS S3150-8T2F Switch admin web interface. The 'button' and 'button_url' GET parameters are used to populate page elements without sufficient sanitization or encoding. An unauthenticated remote attacker can exploit this by crafting a URL containing malicious HTML or JavaScript. If a logged-in user visits this URL, the script executes in their browser context, potentially leading to session hijacking (via document.cookie theft) or unauthorized configuration changes. The vulnerability was identified in firmware version 2.2.0D Build 118101.

Affected products

  • FS Inc S3150-8T2F Switch 2.2.0D Build 118101

Timeline

  • 2025-07: other: Vulnerability discovered
  • 2026-07-31: disclosed: CVE published

References