CVE-2026-27870 PUBLISHED

CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDAT

Assigner: HackRTU
Reserved: 24.02.2026 Published: 17.06.2026 Updated: 17.06.2026

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS)  payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor Teldat
Product Regesta Smart HD-PLC - TLDPH16D2
Versions Default: unknown
  • Version 11.02.05.10.02 is affected
  • Version 11.02.06.00.02 is unaffected

Solutions

The provider has implement the new version 11.02.06.00.02 which solves the security problems detected in the affected version. The end user has to download the new version in the Teldat - Client Support Portal and implement it in the device ( https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US ).

Credits

  • Aarón Flecha Menéndez finder
  • Víctor Bello Cuevas finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-242 Code Injection
  • CAPEC-63 Cross-Site Scripting (XSS)