Open Redirect Vulnerability in GridTime 3000 GNSS Time Server by Microchip
CVE-2026-12622

5.3MEDIUM

Key Information:

Vendor

Microchip

Vendor
CVE Published:
19 June 2026

What is CVE-2026-12622?

The GridTime 3000 GNSS Time Server, developed by Microchip, contains an open redirect vulnerability affecting its password change form submission. This flaw could allow an attacker to redirect users to an untrusted site, potentially leading to phishing attacks or other malicious activities. The vulnerability affects specific versions of the product, highlighting the importance of keeping software updated to mitigate risks.

Affected Version(s)

GridTime 3000 1.0r0.03 <= 1.1r0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.