Cross Site Scripting Vulnerability in BIVOCOM TR321 Wireless Component
CVE-2026-6999

4.8MEDIUM

Key Information:

Vendor

Bivocom

Status
Vendor
CVE Published:
25 April 2026

What is CVE-2026-6999?

A security flaw has been identified in the wireless settings component of BIVOCOM TR321 version 21.1.1.50, allowing remote attackers to manipulate the Network Name SSID. This could lead to cross site scripting (XSS) attacks, enabling unauthorized access to sensitive information. Despite attempts to notify the vendor regarding this vulnerability, there has been no response. Users are advised to review their systems for potential exposure and implement appropriate security measures.

Affected Version(s)

TR321 21.1.1.50

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fergod (VulDB User)
VulDB CNA Team
.