Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Industrial Ethernet 1000 Series Switches - CVE-2026-20232
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in the context of another user.
The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface when processing user-supplied input in specific pages of the interface. A remote user can inject malicious code into specific pages of the interface to execute arbitrary script code in the context of another user.
User interaction is required for another user of the interface to load the injected content.