CVE-2026-32843

MEDIUM

Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php

Title source: cna
STIX 2.1

Description

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.

Scores

CVSS v4 5.1
EPSS 0.0045
EPSS Percentile 36.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
LinkItONEDevGroup/Location Aware Sensor System (LASS) < commit f06bd20
LinkItONEDevGroup/Location Aware Sensor System (LASS) < f06bd202f37f2a8fafe932feabcb119a292f016e
Published Mar 19, 2026
Tracked Since Mar 19, 2026