Two vulnerabilities in legacy Digi International port server products allow unauthenticated access to restricted resources and stored script injection, with no firmware fix coming for one of them.
Summary
- CISA has published an advisory covering two vulnerabilities in Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices running firmware prior to the 2025 release.
- CVE-2026-12352 allows an unauthenticated attacker to bypass authentication and reach restricted resources; it scores 8.2 (HIGH) under CVSS 4.0.
- CVE-2026-12948 is a stored XSS flaw in the web management interface, exploitable by an authenticated administrator to inject scripts that execute in other users’ browsers.
- Digi International has confirmed it will not release a firmware patch for the XSS vulnerability, citing end-of-life status, and recommends migration to the Digi Connect EZ product line.
- No known active exploitation has been reported to CISA at this time, but affected devices are deployed across critical manufacturing, communications, IT, and transport sectors worldwide.
What Has Been Disclosed
CISA published an industrial control systems advisory on 7 July 2026 covering two vulnerabilities in a range of Digi International serial device servers. The affected products — PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA — are used across sectors including critical manufacturing, communications, information technology, and transportation systems, and are deployed worldwide. The vulnerabilities were reported to CISA by nviCloud.
The Authentication Bypass: CVE-2026-12352
The more serious of the two issues is CVE-2026-12352, an incorrect authorisation flaw classified under CWE-863. An unauthenticated actor can exploit it to bypass authentication controls and gain access to restricted resources on the device. It carries a CVSS 3.1 base score of 5.9 (MEDIUM), though under the newer CVSS 4.0 scoring it rises to 8.2 (HIGH). The attack is network-based and requires no privileges or user interaction, though the complexity is rated high. For any device with its web management interface reachable from an untrusted network, this represents a meaningful exposure.
The Stored XSS: CVE-2026-12948
The second vulnerability, CVE-2026-12948, is a stored cross-site scripting flaw in the same web management interface. An authenticated administrator can inject malicious script into certain system configuration fields; that script will subsequently execute in the browser of any user who views the affected pages. The CVSS 3.1 score is 3.8 (LOW), and 4.8 (MEDIUM) under CVSS 4.0. While the attack requires administrator-level credentials to write the affected fields, this is relevant in environments with multiple administrators or where credential compromise is a realistic scenario.
No Patch Coming for the XSS Flaw
The vendor’s position on CVE-2026-12948 is significant for planning purposes: Digi International has stated it will not provide a firmware fix for the affected products, which it describes as approaching end-of-life. The long-term recommendation from the vendor is to migrate to the Digi Connect EZ or Digi Connect EZ TS product lines. For organisations that cannot migrate immediately, the advisory outlines a set of compensating controls rather than a patching path.
Interim Mitigations Available
For the PortServer TS, Digi International advises enabling HTTPS on the web server as a vendor fix, or disabling the web server entirely when it is not in active use. For the Digi One SP, Digi One SP IA, and Digi One IA, the guidance is to disable the web server. Where neither option is immediately practical, the vendor recommends restricting access via firewall or VPN and limiting web management interface access to trusted administrative hosts only. Devices should be deployed on trusted network segments and not exposed to untrusted or public networks. CISA echoes the standard guidance that ICS devices should not be accessible from the internet.
Why it matters
Serial device servers sit at the boundary between IT networks and operational technology, managing serial-to-network connectivity for industrial and communications equipment. An unauthenticated authentication bypass on a network-accessible device in this class is a direct path to disrupting or manipulating connected systems. The vendor’s decision not to patch the XSS vulnerability is a clear signal that these products are at end-of-life, and any organisation still relying on them needs to treat them as permanently unpatched assets. The exposure is not theoretical — these devices are in active use across critical sectors globally, and the combination of legacy firmware, an unpatched flaw, and potential internet exposure is a risk that warrants a formal review rather than a deferred response.
What to do now
- Audit your environment for Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices running firmware prior to Firmware_2025.
- For PortServer TS devices, enable HTTPS on the web server or disable the web server when not actively needed for configuration.
- For Digi One SP, Digi One SP IA, and Digi One IA devices, disable the web server.
- Where web server changes cannot be made immediately, restrict access to the management interface via firewall or VPN, limiting access to trusted administrative hosts only.
- Ensure none of the affected devices are directly accessible from the internet or untrusted network segments.
- Safeguard administrator credentials for affected devices, as exploitation of the XSS vulnerability requires authenticated administrator access.
- Begin planning migration to the Digi Connect EZ or Digi Connect EZ TS product lines, given the vendor’s confirmation that no firmware fix will be issued for CVE-2026-12948.
- Contact Digi International support for assistance with remediation or migration guidance.
