Digi International Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Digi International products.
Products
- Digi PortServer TS3 vulnerabilities
- Digi One IA2 vulnerabilities
- Digi One SP IA2 vulnerabilities
- Digi 6350-SR1 vulnerability
- Digi CM Console Server1 vulnerability
- Digi Connect ES1 vulnerability
- Digi Connect SP1 vulnerability
- Digi ConnectCore 8X products1 vulnerability
- Digi ConnectPort LTS 8/16/321 vulnerability
- Digi ConnectPort TS 8/161 vulnerability
- Digi One IAP1 vulnerability
- Digi One IAP Family1 vulnerability
- Digi One SP1 vulnerability
- Digi One SP / SP IA / IA1 vulnerability
- Digi One SP/Digi One SP IA/Digi One IA1 vulnerability
- Digi Passport Console Server1 vulnerability
- Digi PortServer TS M MEI1 vulnerability
- Digi PortServer TS MEI1 vulnerability
- Digi PortServer TS MEI Hardened1 vulnerability
- Digi PortServer TS P MEI1 vulnerability
- Digi RealPort1 vulnerability
- Digi WR11 XT1 vulnerability
- Digi WR211 vulnerability
- Digi WR311 vulnerability
- Digi WR44 R1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12948MEDIUM | Stored Cross-Site Scripting (XSS)A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79). CWE-79Jul 7, 2026 | CVSS4.8v4.0 | EPSS0.269% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12352MEDIUM | Incorrect AuthorizationThis vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device. CWE-863Jul 7, 2026 | CVSS5.9v3.1 | EPSS0.259% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3659CRITICAL | Improper authentication handling for Digi PortServer TS; Digi One SP, SP IA, IA; Digi One IAPImproper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to m… CWE-287May 12, 2025 | CVSS9.4v4.0 | EPSS0.307% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4299CRITICAL | Digi RealPort Protocol Use of Password Hash Instead of Password for AuthenticationDigi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. CWE-836Aug 31, 2023 | CVSS9.0v3.1 | EPSS0.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-38412CRITICAL | Digi PortServer TS 16 Improper AuthenticationProperly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in. | CVSS9.6v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |