A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 22:16
Updated : 2026-08-12 21:00
NVD link : CVE-2026-19061
Mitre link : CVE-2026-19061
CVE.ORG link : CVE-2026-19061
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity
