CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Digi International PortServer TS, Digi One SP IA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 548

As cited

Copy frozen at (site build).

vulnerabilities

Digi International PortServer TS, Digi One SP IA

Digi International PortServer TS and Digi One SP series devices contain two vulnerabilities in firmware versions prior to 2025: an authentication bypass (CVE-2026-12352) that allows unauthenticated access to restricted resources, and a stored cross-site scripting (XSS) flaw (CVE-2026-12948) in the web management interface. Digi recommends upgrading to Digi Connect EZ models or applying mitigations including enabling HTTPS, disabling unused web servers, and restricting network access.

Why it matters: Organizations deploying these serial console and device management appliances in critical manufacturing, communications, transportation, and IT environments worldwide face immediate risk of unauthorized access and credential theft; administrators should prioritize firmware updates or apply compensating controls such as HTTPS enablement and network segmentation to limit exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Digi International PortServer TS, Digi One SP IA

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Digi International PortServer TS, Digi One SP IA

Digi International disclosed vulnerabilities CVE-2026-12352 and CVE-2026-12948 affecting PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices. CVE-2026-12352 allows unauthenticated attackers to bypass authentication and access restricted resources, while CVE-2026-12948 is a stored cross-site scripting (XSS) flaw in the web management interface that requires authenticated administrator access. Affected firmware versions are prior to Firmware_2025, and Digi recommends upgrading to Digi Connect EZ or Digi Connect EZ TS, or applying mitigations such as enabling HTTPS, disabling the web server, and restricting access via firewall or virtual private network (VPN).

Why it matters: Organizations deploying these Digi devices in critical infrastructure across manufacturing, communications, IT, and transportation sectors must immediately patch or isolate affected units to prevent unauthenticated access to management interfaces and credential compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Digi International PortServer TS, Digi One SP IA

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Digi International PortServer TS, Digi One SP IA

Digi International disclosed two vulnerabilities in PortServer TS and Digi One devices: CVE-2026-12352 allows unauthenticated attackers to bypass authentication and access restricted resources, and CVE-2026-12948 is a stored cross-site scripting flaw in the web management interface that permits authenticated administrators to inject malicious scripts. Affected firmware versions are earlier than Firmware_2025, and Digi recommends upgrading to Digi Connect EZ or Digi Connect EZ TS as the long-term fix.

Why it matters: Organizations deploying Digi PortServer TS or Digi One devices in critical manufacturing, communications, and transportation sectors must patch or apply compensating controls immediately, as the authentication bypass exposes unauthenticated remote access and the XSS vulnerability enables privilege escalation through script injection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Digi International PortServer TS, Digi One SP IA

Digi International disclosed two vulnerabilities in PortServer TS and Digi One devices: CVE-2026-12352 allows unauthenticated attackers to bypass authentication and access restricted resources, and CVE-2026-12948 is a stored cross-site scripting flaw in the web management interface that permits authenticated administrators to inject malicious scripts. Affected firmware versions are earlier than Firmware_2025, and Digi recommends upgrading to Digi Connect EZ or Digi Connect EZ TS as the long-term fix.

Why it matters: Organizations deploying Digi PortServer TS or Digi One devices in critical manufacturing, communications, and transportation sectors must patch or apply compensating controls immediately, as the authentication bypass exposes unauthenticated remote access and the XSS vulnerability enables privilege escalation through script injection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary