CVE-2026-12620

The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microchip:gridtime_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:microchip:gridtime_3000:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-19 16:16

Updated : 2026-07-09 15:55


NVD link : CVE-2026-12620

Mitre link : CVE-2026-12620

CVE.ORG link : CVE-2026-12620


JSON object : View

Products Affected

microchip

  • gridtime_3000
  • gridtime_3000_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo