CVE-2018-5303: Impinj r420 Rfid Reader Firmware

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the web application is vulnerable to Cross Site Scripting; this vulnerability allows an attacker to send malicious code to another user.

Affected products

  • Impinj r420 Rfid Reader Firmware: before 2.2.2 (fixed in 2.2.2)

Published 2018-05-11. Last modified 2026-06-17.