Description
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject
a specific payload via the parameter "cmdcookie" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This issue affects Regesta Smart HD-PLC - TLDPH16D2: 
11.02.06.00.02
Published: 2026-09-25
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS) in Regesta Smart HD‑PLC
Action: Apply Patch
AI Analysis

Impact

An attacker who has network access to the Regesta Smart HD‑PLC firmware and has completed the required registration can inject a crafted payload into the cmdcookie query parameter of the /upgrade/index.html page. The device does not encode or sanitize this parameter before rendering, allowing the payload to be executed as client‑side script when the page is accessed. This vulnerability permits arbitrary client‑side code execution within the context of the PLC’s web interface.

Affected Systems

Teldat Regesta Smart HD‑PLC – TLDPH16D2 firmware version 11.02.06.00.02 is affected. The vendor has released firmware 11.02.06.00.03 that resolves the issue; the firmware version should be updated to that release or later.

Risk and Exploitability

The vulnerability can be exploited by an attacker who has network reach to the device and has performed the required registration. By sending a crafted HTTP request to /upgrade/index.html with a malicious cmdcookie value, the unescaped payload executes in the client’s browser. Because the flaw is client‑side, it does not grant device control, but it allows arbitrary script execution within the context of the web UI. The CVSS score of 4.8 indicates moderate severity, the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Thus exploitation is possible but is limited to client‑side impact and relies on the attacker’s ability to reach the device.

Generated by OpenCVE AI on September 25, 2026 at 12:53 UTC.

Remediation

Vendor Solution

The provider has implemented the new version 11.02.06.00.03 which solves the security problems detected in the affected version. The end user has to download the new version in the Teldat - Client Support Portal and implement it in the device ( https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US ).


OpenCVE Recommended Actions

  • Download and install firmware 11.02.06.00.03 from Teldat’s Client Support Portal and deploy it to the affected device.
  • Reboot the PLC after the firmware update to ensure all services load the new code.
  • If the device cannot be updated immediately, isolate it or block network access to the /upgrade/index.html endpoint so that the cmdcookie parameter cannot be used by external actors until the patch is applied.

Generated by OpenCVE AI on September 25, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject a specific payload via the parameter "cmdcookie" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This issue affects Regesta Smart HD-PLC - TLDPH16D2:  11.02.06.00.02
Title CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT
First Time appeared Teldat
Teldat regesta Smart Hd-plc - Tldph16d2
Weaknesses CWE-79
CPEs cpe:2.3:a:teldat:regesta_smart_hd-plc_-_tldph16d2:11.02.06.00.02:*:*:*:*:*:*:*
cpe:2.3:a:teldat:regesta_smart_hd-plc_-_tldph16d2:11.02.06.00.03:*:*:*:*:*:*:*
Vendors & Products Teldat
Teldat regesta Smart Hd-plc - Tldph16d2
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Teldat Regesta Smart Hd-plc - Tldph16d2
cve-icon MITRE

Status: PUBLISHED

Assigner: HackRTU

Published:

Updated: 2026-09-25T10:43:05.972Z

Reserved: 2026-02-24T08:59:28.139Z

Link: CVE-2026-27867

cve-icon Vulnrichment

Updated: 2026-09-25T10:43:01.692Z

cve-icon NVD

Status : Received

Published: 2026-09-25T11:17:01.203

Modified: 2026-09-25T11:17:01.203

Link: CVE-2026-27867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T13:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')