CVE-2023-48978: Ncr Itm Web Terminal
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.
Affected products
- Ncr Itm Web Terminal: version 4.4.0 only; version 4.4.4 only
Published 2025-06-23. Last modified 2026-06-17.