CVE-2026-12948: Digi International Digi One Ia

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).

Affected products

Published 2026-07-07. Last modified 2026-07-13.