{"id":"CVE-2026-27867","title":"An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject\na specific payload via the parameter \"cmdcookie\" …","summary":"An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject\na specific payload via the parameter \"cmdcookie\" …","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-79"],"vendor":"Teldat","product":"Regesta Smart HD-PLC - TLDPH16D2","affected":["regesta_smart_hd-plc_-_tldph16d2 11.02.06.00.02"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:01.203","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-27867","references":[{"url":"https://support.teldat.com/images/content/docs/Teldat_dm1087_regesta_smart_nessum_series_installation(1).pdf","label":"ffb98d57-deaa-4918-a669-5225ccc13e39"},{"url":"https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US","label":"ffb98d57-deaa-4918-a669-5225ccc13e39"},{"url":"https://www.hackrtu.com/blog/CNA-CVE-2026-27867/","label":"ffb98d57-deaa-4918-a669-5225ccc13e39"},{"url":"https://www.hackrtu.com/blog/CNA-HRTU-0004/","label":"ffb98d57-deaa-4918-a669-5225ccc13e39"},{"url":"https://www.teldat.com/es/","label":"ffb98d57-deaa-4918-a669-5225ccc13e39"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-25T10:42:56.136783Z"},"cvssSource":"cna","ingestedAt":"2026-09-25T11:06:38.802Z","slug":"CVE-2026-27867","body":"## Overview\n\nAn attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject\na specific payload via the parameter \"cmdcookie\" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This issue affects Regesta Smart HD-PLC - TLDPH16D2: \n11.02.06.00.02\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}