Description
AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Stored cross-site scripting allowing credential theft and session hijack
Action: Immediate Patch
AI Analysis

Impact

AJA HELO Plus firmware versions before 2.1.7 contain a stored cross‑site scripting vulnerability (CWE‑79) that enables unauthenticated attackers with network access to inject malicious JavaScript via the unsanitized eParamID_SystemName value submitted to the /config?action=set web configuration API. The injected script runs in the context of any administrator who visits the web management interface, allowing the attacker to capture stored secrets such as web UI credentials, RTMP stream keys, publish URLs, NFS/SMB share credentials, and to hijack the authenticated session.

Affected Systems

The affected product is AJA Video Systems HELO Plus firmware before version 2.1.7. Any device running a firmware release lower than 2.1.7 is vulnerable, regardless of other configuration settings, including those that have authentication disabled.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and while an EPSS score is not available, the vulnerability can be exploited over the network without authentication, rendering it an attractive target for compromised local users or attackers with network reach to the device. Because the exploit results in persistent credential theft and session hijack, the risk is elevated for environments where the web interface is accessible to untrusted users. The vulnerability is not listed in CISA KEV, but its impact warrants proactive remediation.

Generated by OpenCVE AI on September 30, 2026 at 23:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply firmware version 2.1.7 or newer, which removes the unsanitized input processing.
  • Ensure that device authentication is enabled so that the /config endpoint cannot be accessed by unauthenticated users.
  • Restrict network access to the device’s web interface to trusted IP ranges or employ a firewall rule to block external traffic to the /config action if immediate patching cannot occur.

Generated by OpenCVE AI on September 30, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.
Title AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T22:02:09.294Z

Reserved: 2026-05-18T19:22:26.747Z

Link: CVE-2026-47096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T22:16:33.720

Modified: 2026-09-30T22:16:33.720

Link: CVE-2026-47096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')