Junglewise Threat Intelligence

CVE-2026-9144: Taiko AG1000-01A SMS Alert Gateway stored XSS in web configuration

CVE-2026-9144 · Severity: high · CVSS 7.6 · Published 2026-05-20

Technologies: Taiko AG1000-01A SMS Alert Gateway. Vendors: Taiko.

Executive brief

The Taiko AG1000-01A SMS Alert Gateway, a device used to send SMS notifications for system alerts, contains a security flaw in its web management interface. An attacker with low-level access can inject malicious code that remains on the device's dashboard. When an administrator views the dashboard, this code could allow the attacker to hijack the administrator's session, potentially leading to unauthorized configuration changes or disruption of alert services.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the web configuration interface of Taiko AG1000-01A SMS Alert Gateway (Rev 7.3 and 8). The flaw is rooted in improper neutralization of input across multiple administrative form fields. Authenticated attackers can bypass front-end character length restrictions by using JavaScript comments and template literals to fragment and then concatenate a malicious payload across several fields. When these fields are rendered together on administrative pages like index.zhtml, the payload executes in the context of the victim's browser session. This can lead to session hijacking or unauthorized administrative actions.

Affected products

  • Taiko AG1000-01A SMS Alert Gateway Rev 7.3, Rev 8, UM-AG1000_R7.2

Timeline

  • 2026-05-20: advisory: NVD published the CVE record based on VulnCheck data.

References

Related threats