Executive brief
A security vulnerability exists in the BIVOCOM TR321 industrial router, specifically within its wireless configuration interface. An attacker with administrative access can inject malicious scripts into the network name (SSID) field, which could then execute in the browser of other administrators viewing the settings. This could lead to unauthorized actions being performed in the router's management console, though the overall risk is considered low due to the high level of access required.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the BIVOCOM TR321 router version 21.1.1.50. The flaw is located in the 'Wireless Setting' component where the 'Network Name SSID' argument is improperly neutralized before being rendered in the web interface. A remote attacker with high privileges (PR:H) can manipulate this argument to inject arbitrary web scripts. The vulnerability requires user interaction (UI:R) from another administrator to execute. While an exploit has been published, the impact is limited to integrity (I:L) within the context of the management session. The vendor was reportedly contacted but did not respond; users are advised to upgrade the affected component if a patch becomes available.
Affected products
- BIVOCOM TR321 21.1.1.50
Timeline
- 2026-04-25: disclosed: Initial disclosure of the vulnerability
- 2026-04-25: advisory: CVE-2026-6999 published by VulDB/NVD