Description
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
Published: 2026-07-07
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting flaw exists in the web management interface of several Digi International devices, allowing a remote, authenticated administrator to inject malicious JavaScript into select configuration fields. Once stored, the payload is executed each time a user visits the affected pages, running in that user’s browser context. This can lead to theft or manipulation of data displayed or processed in the browser, compromising confidentiality and integrity for end users that view the insecure pages.

Affected Systems

The vulnerability applies to Digi One IA, Digi One SP, Digi One SP IA, and Digi PortServer TS devices. No firmware or hardware version restriction is documented, so any installed firmware that provides the exposed web interface and contains the vulnerable configuration fields is at risk. Administrators should verify that their firmware version includes the applicable fix or a patch that mitigates the issue.

Risk and Exploitability

The CVSS score of 4.8 reflects a medium severity, and the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The flaw requires the attacker to be an authenticated administrator; however, once a malicious script is stored, it can impact any user who later views the affected page. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known active exploits at this time. The attack path is limited to users with management interface access, but the stored nature of the script enables broader impact across all users of the system.

Generated by OpenCVE AI on July 26, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version that includes the XSS fix, following Digi International’s security advisory releases.
  • Limit access to the web management interface to a trusted internal network segment only, and enforce strong authentication controls for all administrator accounts.
  • Require multi‑factor authentication for all administrative logins to reduce the risk of credential compromise.
  • Deploy a web application firewall or configure a content‑security‑policy header on the device’s web interface to block or warn against execution of unexpected scripts.

Generated by OpenCVE AI on July 26, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Digi International
Digi International digi One Ia
Digi International digi One Sp
Digi International digi One Sp Ia
Digi International digi Portserver Ts
Vendors & Products Digi International
Digi International digi One Ia
Digi International digi One Sp
Digi International digi One Sp Ia
Digi International digi Portserver Ts

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
Title Stored Cross-Site Scripting (XSS)
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digi International Digi One Ia Digi One Sp Digi One Sp Ia Digi Portserver Ts
cve-icon MITRE

Status: PUBLISHED

Assigner: Digi

Published:

Updated: 2026-07-13T16:19:13.748Z

Reserved: 2026-06-22T20:33:02.985Z

Link: CVE-2026-12948

cve-icon Vulnrichment

Updated: 2026-07-07T14:56:19.293Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')