Executive brief
Limatek LimRAD NAC, a network access control solution used to manage and secure device connections to a corporate network, contains a security flaw. This vulnerability allows an attacker to inject malicious scripts into the system's management interface. If an administrator views the affected page, the attacker could potentially perform unauthorized actions or steal session information, though the vendor has not yet responded to the report.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Limatek System Inc. LimRAD NAC through version 08072026. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with low-privileged access on an adjacent network can inject malicious scripts that are stored on the server and executed in the context of another user's browser, typically requiring some user interaction. This could lead to unauthorized information disclosure or integrity violations within the management console. As of the disclosure date, the vendor has not responded to the report, and no patch has been confirmed.
Affected products
- Limatek System Inc. LimRAD NAC through 08072026
Timeline
- 2026-07-08: disclosed: Vulnerability published by TR-CERT
- 2026-07-08: advisory: CVE-2026-6371 published to NVD