{"id":"CVE-2026-27867","published":"2026-09-25T11:17:01.203","lastModified":"2026-09-25T11:17:01.203","description":"An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject\na specific payload via the parameter \"cmdcookie\" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This issue affects Regesta Smart HD-PLC - TLDPH16D2: \n11.02.06.00.02","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://support.teldat.com/images/content/docs/Teldat_dm1087_regesta_smart_nessum_series_installation(1).pdf","tags":[]},{"url":"https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US","tags":[]},{"url":"https://www.hackrtu.com/blog/CNA-CVE-2026-27867/","tags":[]},{"url":"https://www.hackrtu.com/blog/CNA-HRTU-0004/","tags":[]},{"url":"https://www.teldat.com/es/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}