Stored Cross-Site Scripting Vulnerability in AJA HELO Plus
CVE-2026-47096
5.3MEDIUM
What is CVE-2026-47096?
The AJA HELO Plus firmware prior to version 2.1.7 is susceptible to a stored cross-site scripting vulnerability. This flaw permits unauthenticated attackers with access to the network to inject malicious JavaScript. This is done by setting an unsanitized eParamID_SystemName value via the /config?action=set web configuration API. If device authentication is disenabled, attackers can persistently execute arbitrary scripts in the browser of any administrator accessing the web management interface. Consequently, this can lead to theft of sensitive information such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as session hijacking of authenticated users.
Affected Version(s)
HELO Plus 0 < 2.1.7
