CVE-2018-19926: Zenitel IP-Stationweb Firmware

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.

Affected products

  • Zenitel IP-Stationweb Firmware: before 4.2.3.9 (fixed in 4.2.3.9)

Published 2018-12-06. Last modified 2026-06-17.