Stored Cross-Site Scripting in Hereta ETH-IMC408M Firmware
CVE-2026-29513

5.1MEDIUM

What is CVE-2026-29513?

The Hereta ETH-IMC408M firmware versions up to 1.0.15 are vulnerable to a stored cross-site scripting attack. This vulnerability exists due to insufficient input validation in the Device Location field within the System Status interface. Authenticated attackers can exploit this by injecting arbitrary JavaScript code, which subsequently executes in the browsers of users accessing the status page. This can lead to unauthorized actions, data exposure, or further compromises within the affected environment. It is critical for users of these firmware versions to apply the necessary security patches and implement additional security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Hereta ETH-IMC408M 0 <= 1.0.15

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
.