Stored Cross-Site Scripting in Hereta ETH-IMC408M Firmware
CVE-2026-29513
Key Information:
- Status
- Vendor
- CVE Published:
- 16 March 2026
What is CVE-2026-29513?
The Hereta ETH-IMC408M firmware versions up to 1.0.15 are vulnerable to a stored cross-site scripting attack. This vulnerability exists due to insufficient input validation in the Device Location field within the System Status interface. Authenticated attackers can exploit this by injecting arbitrary JavaScript code, which subsequently executes in the browsers of users accessing the status page. This can lead to unauthorized actions, data exposure, or further compromises within the affected environment. It is critical for users of these firmware versions to apply the necessary security patches and implement additional security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Hereta ETH-IMC408M 0 <= 1.0.15
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
