CVE-2026-29520

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping_ipaddr parameter to compromise authenticated administrator sessions when the links are visited.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:*

History

10 Apr 2026, 17:43

Type Values Removed Values Added
Summary
  • (es) El firmware Hereta ETH-IMC408M versión 1.0.15 y anteriores contienen una vulnerabilidad de cross-site scripting reflejado en la función de ping de Diagnóstico de Red que permite a los atacantes ejecutar JavaScript arbitrario. Los atacantes pueden crear enlaces maliciosos con cargas útiles de script inyectadas en el parámetro ping_ipaddr para comprometer sesiones de administrador autenticadas cuando se visitan los enlaces.
First Time Hereta eth-imc408m Firmware
Hereta eth-imc408m
Hereta
CPE cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:*
cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:*
References () https://web.archive.org/web/20250820105319/http://hereta.com/ - () https://web.archive.org/web/20250820105319/http://hereta.com/ - Product
References () https://www.vulncheck.com/advisories/hereta-eth-imc408m-reflected-xss-via-ping-ipaddr-parameter - () https://www.vulncheck.com/advisories/hereta-eth-imc408m-reflected-xss-via-ping-ipaddr-parameter - Third Party Advisory

17 Mar 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

16 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 18:16

Updated : 2026-04-10 17:43


NVD link : CVE-2026-29520

Mitre link : CVE-2026-29520

CVE.ORG link : CVE-2026-29520


JSON object : View

Products Affected

hereta

  • eth-imc408m_firmware
  • eth-imc408m
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')