CVE-2018-5304: Impinj r420 Rfid Reader Firmware
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party application or perform other malicious actions.
Affected products
- Impinj r420 Rfid Reader Firmware: before 2.2.2 (fixed in 2.2.2)
Published 2018-05-11. Last modified 2026-06-17.