a specific payload via the parameter "cmdcookie" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This issue affects Regesta Smart HD-PLC - TLDPH16D2:
11.02.06.00.02
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The provider has implemented the new version 11.02.06.00.03 which solves the security problems detected in the affected version. The end user has to download the new version in the Teldat - Client Support Portal and implement it in the device ( https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US ).
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject a specific payload via the parameter "cmdcookie" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.06.00.02 | |
| Title | CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT | |
| First Time appeared |
Teldat
Teldat regesta Smart Hd-plc - Tldph16d2 |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:teldat:regesta_smart_hd-plc_-_tldph16d2:11.02.06.00.02:*:*:*:*:*:*:* cpe:2.3:a:teldat:regesta_smart_hd-plc_-_tldph16d2:11.02.06.00.03:*:*:*:*:*:*:* |
|
| Vendors & Products |
Teldat
Teldat regesta Smart Hd-plc - Tldph16d2 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: HackRTU
Published:
Updated: 2026-09-25T10:43:05.972Z
Reserved: 2026-02-24T08:59:28.139Z
Link: CVE-2026-27867
Updated: 2026-09-25T10:43:01.692Z
Status : Received
Published: 2026-09-25T11:17:01.203
Modified: 2026-09-25T11:17:01.203
Link: CVE-2026-27867
No data.
OpenCVE Enrichment
No data.