The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-08 22:17
Updated : 2026-07-09 16:39
NVD link : CVE-2026-5922
Mitre link : CVE-2026-5922
CVE.ORG link : CVE-2026-5922
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
