A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.
References
Configurations
No configuration.
History
12 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 |
12 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 19:16
Updated : 2026-06-17 10:22
NVD link : CVE-2026-23819
Mitre link : CVE-2026-23819
CVE.ORG link : CVE-2026-23819
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
