Impact
AJA HELO Plus firmware versions before 2.1.7 contain a stored cross‑site scripting vulnerability (CWE‑79) that enables unauthenticated attackers with network access to inject malicious JavaScript via the unsanitized eParamID_SystemName value submitted to the /config?action=set web configuration API. The injected script runs in the context of any administrator who visits the web management interface, allowing the attacker to capture stored secrets such as web UI credentials, RTMP stream keys, publish URLs, NFS/SMB share credentials, and to hijack the authenticated session.
Affected Systems
The affected product is AJA Video Systems HELO Plus firmware before version 2.1.7. Any device running a firmware release lower than 2.1.7 is vulnerable, regardless of other configuration settings, including those that have authentication disabled.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and while an EPSS score is not available, the vulnerability can be exploited over the network without authentication, rendering it an attractive target for compromised local users or attackers with network reach to the device. Because the exploit results in persistent credential theft and session hijack, the risk is elevated for environments where the web interface is accessible to untrusted users. The vulnerability is not listed in CISA KEV, but its impact warrants proactive remediation.
OpenCVE Enrichment