Digi PortServer TS auth bypass flaw disclosed
CISA warns of an authentication bypass and stored XSS in Digi International PortServer TS and Digi One SP/IA devices, with no active exploitation reported yet.
CISA published an ICS advisory detailing two vulnerabilities affecting Digi International's PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA serial-to-network devices, which are deployed worldwide across critical manufacturing, communications, IT, and transportation sectors. The more serious flaw, CVE-2026-12352, allows an unauthenticated attacker to bypass authentication and access restricted resources on the device, potentially exposing credentials. The second, CVE-2026-12948, is a stored cross-site scripting vulnerability that lets an authenticated administrator inject malicious scripts into configuration fields, which then execute in the browser of anyone viewing the affected pages.
All affected products are running firmware prior to the 2025 release. Digi International will not issue a firmware fix for the XSS vulnerability since the affected products are approaching end-of-life, instead recommending migration to the Digi Connect EZ or Digi Connect EZ TS line. For the authentication bypass, vendor mitigations include enabling HTTPS or disabling the web server when not in use, alongside standard network segmentation, firewall/VPN restriction of management interfaces, and credential safeguarding.
CISA states no known public exploitation of these vulnerabilities has been reported at this time. The vulnerabilities were responsibly disclosed to CISA by researcher nviCloud, and the advisory recommends organizations minimize internet exposure of ICS devices and follow defense-in-depth practices.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free