Impact
An attacker who has network access to the Regesta Smart HD‑PLC firmware and has completed the required registration can inject a crafted payload into the cmdcookie query parameter of the /upgrade/index.html page. The device does not encode or sanitize this parameter before rendering, allowing the payload to be executed as client‑side script when the page is accessed. This vulnerability permits arbitrary client‑side code execution within the context of the PLC’s web interface.
Affected Systems
Teldat Regesta Smart HD‑PLC – TLDPH16D2 firmware version 11.02.06.00.02 is affected. The vendor has released firmware 11.02.06.00.03 that resolves the issue; the firmware version should be updated to that release or later.
Risk and Exploitability
The vulnerability can be exploited by an attacker who has network reach to the device and has performed the required registration. By sending a crafted HTTP request to /upgrade/index.html with a malicious cmdcookie value, the unescaped payload executes in the client’s browser. Because the flaw is client‑side, it does not grant device control, but it allows arbitrary script execution within the context of the web UI. The CVSS score of 4.8 indicates moderate severity, the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Thus exploitation is possible but is limited to client‑side impact and relies on the attacker’s ability to reach the device.
OpenCVE Enrichment