Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Industrial Ethernet 1000 Series Switches - CVE-2026-20232

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Industrial Ethernet 1000 Series Switches - CVE-2026-20232

Published: August 19, 2026


Vulnerability identifier: #VU144383
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20232
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script code in the context of another user.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface when processing user-supplied input in specific pages of the interface. A remote user can inject malicious code into specific pages of the interface to execute arbitrary script code in the context of another user.

User interaction is required for another user of the interface to load the injected content.


Affected software

Industrial Ethernet 1000 Series Switches

How to mitigate CVE-2026-20232

Install security update from vendor's website.

Industrial Ethernet 1000 Series Switches - update to 1.9.6

External References

Related Security Bulletins