CVE-2019-14456: Opengear

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server) sends crafted text to a serial port (that has logging enabled), the text will be replayed when the logs are viewed. Exploiting this vulnerability requires access to the serial port and/or console server.

Affected products

  • Opengear Opengear: before 4.5.0 (fixed in 4.5.0)

Published 2019-07-31. Last modified 2026-06-17.