mediumOther

Digi International PortServer TS, Digi One SP/SP IA/IA - Authentication Bypass and Stored XSS

First seen Jul 9, 2026 · Updated Jul 9, 2026 · CVSS 8.2

icsotauthentication-bypassxssend-of-lifecisa-advisory

CISA disclosed two vulnerabilities in Digi International's PortServer TS and Digi One SP/SP IA/IA serial-to-network devices: an authentication bypass allowing unauthenticated access to restricted web resources, and a stored XSS flaw exploitable by authenticated administrators. These are legacy, end-of-life industrial devices used across critical manufacturing, communications, IT, and transportation sectors, with no vendor firmware fix planned for the XSS issue.

Technical Analysis

CVE-2026-12352 (CWE-863, CVSS v3.1 5.9/CVSS v4.0 8.2) allows an unauthenticated remote attacker to bypass authentication and access restricted resources on the device's web management interface, potentially exposing credentials. CVE-2026-12948 (CWE-79, CVSS v3.1 3.8/CVSS v4.0 4.8) is a stored XSS vulnerability requiring authenticated administrator access to inject malicious scripts into configuration fields, which then execute in the browser of any user viewing those pages. Both flaws affect legacy PortServer TS and Digi One SP/SP IA/IA firmware predating the 2025 release, and the vendor will not patch the XSS issue since these products are approaching end-of-life, recommending migration to Digi Connect EZ instead. These are OT/ICS serial device management interfaces rather than components typically integrated into AI agent or LLM pipelines, so there is no plausible direct impact to AI agent systems; however, organizations using these devices to manage network access for broader IT/OT-converged environments (including any hosts running agent frameworks) should ensure the compromised credentials or session hijacking via XSS cannot cascade into adjacent systems.

Affected Systems

Digi International PortServer TS (firmware < 2025), Digi One SP (firmware < 2025), Digi One SP IA (firmware < 2025), Digi One IA (firmware < 2025)

Indicators of Compromise

  • No known IOCs published; no public exploitation reported by CISA at this time.

Remediation Steps

  1. 1

    Upgrade hardware

    Migrate to Digi Connect EZ or Digi Connect EZ TS as the recommended long-term solution since affected products are end-of-life.

  2. 2

    Enable HTTPS

    For PortServer TS, enable HTTPS on the web server to mitigate the authentication bypass.

  3. 3

    Disable web server when unused

    For Digi One SP/SP IA/IA, disable the web management interface when not actively needed for configuration.

  4. 4

    Restrict network access

    Place devices behind a firewall or VPN, restrict web management interface access to trusted administrative hosts, and avoid exposing devices to untrusted or public networks.

  5. 5

    Protect administrator credentials

    Safeguard admin credentials since XSS exploitation requires authenticated admin access to write malicious content into configuration fields.

  6. 6

    Contact vendor support

    Reach out to Digi International support (https://www.digi.com/support) for further assistance and guidance.

CVE / Advisory IDs

CVE-2026-12352CVE-2026-12948

Industries Most Exposed

Critical ManufacturingCommunicationsInformation TechnologyTransportation Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.