---
id: CVE-2026-97871
title: A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76
summary: >-
  A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue
  affects the function OpenLocalBrowser of the file
  ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation
  of the argument url leads to c…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
vendor: Zhonglun
product: CloudPos
affected:
  - CloudPos 3.0.1.0
  - CloudPos 3.0.1.1
  - CloudPos 3.0.1.2
  - CloudPos 3.0.1.3
  - CloudPos 3.0.1.4
  - CloudPos 3.0.1.5
  - CloudPos 3.0.1.6
  - CloudPos 3.0.1.7
  - CloudPos 3.0.1.8
  - CloudPos 3.0.1.9
  - CloudPos 3.0.1.10
  - CloudPos 3.0.1.11
  - CloudPos 3.0.1.12
  - CloudPos 3.0.1.13
  - CloudPos 3.0.1.14
  - CloudPos 3.0.1.15
  - CloudPos 3.0.1.16
  - CloudPos 3.0.1.17
  - CloudPos 3.0.1.18
  - CloudPos 3.0.1.19
  - CloudPos 3.0.1.20
  - CloudPos 3.0.1.21
  - CloudPos 3.0.1.22
  - CloudPos 3.0.1.23
  - CloudPos 3.0.1.24
  - CloudPos 3.0.1.25
  - CloudPos 3.0.1.26
  - CloudPos 3.0.1.27
  - CloudPos 3.0.1.28
  - CloudPos 3.0.1.29
  - CloudPos 3.0.1.30
  - CloudPos 3.0.1.31
  - CloudPos 3.0.1.32
  - CloudPos 3.0.1.33
  - CloudPos 3.0.1.34
  - CloudPos 3.0.1.35
  - CloudPos 3.0.1.36
  - CloudPos 3.0.1.37
  - CloudPos 3.0.1.38
  - CloudPos 3.0.1.39
  - CloudPos 3.0.1.40
  - CloudPos 3.0.1.41
  - CloudPos 3.0.1.42
  - CloudPos 3.0.1.43
  - CloudPos 3.0.1.44
  - CloudPos 3.0.1.45
  - CloudPos 3.0.1.46
  - CloudPos 3.0.1.47
  - CloudPos 3.0.1.48
  - CloudPos 3.0.1.49
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:21.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97871'
references:
  - url: >-
      https://github.com/user-attachments/files/30580490/CloudPos.CefSharp.RCE.docx
    label: cna@vuldb.com
  - url: 'https://github.com/xy-f0/CVE/issues/5'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-97871'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/911849'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409887'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409887/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-25T16:41:33.306613Z'
ingestedAt: '2026-09-25T17:13:14.018Z'
---

## Overview

A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
