Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-75937 1 Digi International 12 Anywhereusb Plus Family, Connect Ez Family, Connect It Family and 9 more 2026-10-06 N/A
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
CVE-2026-12352 1 Digi International 2 Digi One Sp / Sp Ia / Ia, Portserver Ts 1/2/4 2026-07-10 5.9 Medium
This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.
CVE-2026-12948 1 Digi International 4 Digi One Ia, Digi One Sp, Digi One Sp Ia and 1 more 2026-07-10 N/A
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).