CVE-2026-12948: Digi International Digi One Ia
Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
Affected products
- Digi International Digi One Ia: from 82000774_Z, up to and including 82000774_AB
- Digi International Digi One SP: from 82000774_Z, up to and including 82000774_AB
- Digi International Digi One SP Ia: from 82000774_Z, up to and including 82000774_AB
- Digi International Digi Portserver Ts: from 82000747_V1, up to and including 82000747_AB
Published 2026-07-07. Last modified 2026-07-13.