Stored Cross-Site Scripting in 1xxx Series NVR Devices by XYZ Corp
CVE-2026-6824
8.4HIGH
What is CVE-2026-6824?
A stored cross-site scripting vulnerability is present in certain 1xxx series NVR devices manufactured by XYZ Corp. This flaw arises from inadequate sanitization of user-supplied input across specific functional modules. By exploiting this weakness, attackers can embed malicious scripts that are persistently stored within the device's backend. Consequently, when administrators or users access the compromised pages, the scripts execute within their browsers, which poses serious risks such as session hijacking, unauthorized actions on the device, or even the theft of sensitive data.
Affected Version(s)
CP-UNR-108F1 Hardware 1.0
CP-UNR-108F1 System 4.001.00AT009.0.R
CP-UNR-108F1 Web 3.2.7.128806
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jithin Nambiar J reported this vulnerability to CISA.
