Stored Cross-Site Scripting Vulnerability in AJA HELO Plus
CVE-2026-47096

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-47096?

The AJA HELO Plus firmware prior to version 2.1.7 is susceptible to a stored cross-site scripting vulnerability. This flaw permits unauthenticated attackers with access to the network to inject malicious JavaScript. This is done by setting an unsanitized eParamID_SystemName value via the /config?action=set web configuration API. If device authentication is disenabled, attackers can persistently execute arbitrary scripts in the browser of any administrator accessing the web management interface. Consequently, this can lead to theft of sensitive information such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as session hijacking of authenticated users.

Affected Version(s)

HELO Plus 0 < 2.1.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saleh Alghamdi
Abdulrahman Aldossary
.