Executive Summary
In July 2026, Digi International disclosed two significant vulnerabilities affecting their PortServer TS and Digi One SP IA devices. The first, CVE-2026-12352, allows unauthenticated attackers to bypass authentication mechanisms, granting unauthorized access to restricted resources. The second, CVE-2026-12948, is a stored cross-site scripting (XSS) vulnerability that enables authenticated administrators to inject malicious scripts into system configuration fields, which execute in the browsers of users viewing the affected pages. These vulnerabilities pose risks of unauthorized access, credential theft, and potential system compromise.
The disclosure of these vulnerabilities underscores the critical importance of securing networked devices, especially those integral to industrial control systems. Organizations must prioritize timely firmware updates and implement robust network segmentation to mitigate such risks. This incident highlights the ongoing challenges in maintaining the security of legacy systems and the necessity for continuous monitoring and proactive defense strategies.
Why This Matters Now
The recent disclosure of vulnerabilities in Digi International's devices highlights the urgent need for organizations to assess and secure their networked equipment. With increasing reliance on industrial control systems, unpatched vulnerabilities can serve as entry points for attackers, leading to significant operational disruptions and data breaches. Immediate action is required to mitigate these risks and protect critical infrastructure.
Attack Path Analysis
An attacker exploited an authentication bypass vulnerability (CVE-2026-12352) in the Digi PortServer TS and Digi One SP IA devices to gain unauthorized access. Subsequently, the attacker leveraged a stored cross-site scripting (XSS) vulnerability (CVE-2026-12948) to inject malicious scripts into system configuration fields. These scripts executed in the browsers of users accessing the affected pages, potentially leading to credential theft or further exploitation. The attacker then established command and control channels to maintain persistent access and exfiltrated sensitive data from the compromised devices. Finally, the attacker may have disrupted device operations, causing service outages or data loss.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited an authentication bypass vulnerability (CVE-2026-12352) to gain unauthorized access to the device's web management interface.
Related CVEs
CVE-2025-3659
CVSS 9.4Improper authentication handling in Digi PortServer TS and Digi One SP IA allows unauthenticated attackers to modify configuration settings via specially crafted HTTP POST requests.
Affected Products:
Digi International PortServer TS – <= 82000747_AA
Digi International Digi One SP – <= 82000774_Z
Digi International Digi One SP IA – <= 82000774_Z
Digi International Digi One IA – <= 82000774_Z
Digi International Digi One IAP – <= 82000770_Z
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Exploitation for Client Execution
Exploit Public-Facing Application
JavaScript
Credentials in Files
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Coding Practices
Control ID: 6.5.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical manufacturing processes using Digi International serial servers face authentication bypass and XSS vulnerabilities, compromising operational technology security and enabling unauthorized industrial system access.
Transportation
Transportation infrastructure relies on Digi PortServer devices for serial connectivity, creating risks of unauthorized access to control systems and potential disruption of critical transportation operations.
Telecommunications
Communication networks utilizing Digi One serial-to-IP devices are vulnerable to authentication bypass attacks, potentially allowing malicious actors to compromise network infrastructure and intercept communications.
Information Technology/IT
IT infrastructure dependent on Digi serial servers faces cross-site scripting and authentication vulnerabilities, requiring immediate firewall restrictions and migration to newer Connect EZ solutions.
Sources
- Digi International PortServer TS, Digi One SP IAhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07Verified
- Improper Authentication Handling for Digi PortServer TS and Digi One SP IAhttps://www.digi.com/getattachment/Resources/Security/Alerts/Improper-authentication-handling-for-Digi-PortServ/improper-authentication-handling.pdfVerified
- CVE-2025-3659 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-3659Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally, establish command and control channels, and exfiltrate data, thereby reducing the overall blast radius of the compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial unauthorized access due to authentication bypass vulnerabilities, it could likely limit the attacker's ability to exploit such access to move laterally or escalate privileges.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to escalate privileges by restricting access to sensitive configuration fields and reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely constrain the attacker's lateral movement by enforcing strict segmentation policies, thereby reducing the reachability of other systems.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and limit unauthorized command and control communications, thereby reducing the attacker's ability to maintain persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit data exfiltration by controlling and monitoring outbound traffic, thereby reducing the risk of sensitive information being transmitted to unauthorized destinations.
While Aviatrix Zero Trust CNSF may not prevent initial service disruptions, it could likely limit the scope of operational impact by containing the attacker's activities and preventing further spread within the network.
Impact at a Glance
Affected Business Functions
- Remote Device Management
- Industrial Control Systems Monitoring
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of device configuration data and unauthorized control over industrial devices.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access to critical resources and limit lateral movement.
- • Deploy East-West Traffic Security controls to monitor and control internal network traffic, detecting unauthorized movements.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to malicious activities promptly.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Regularly update and patch devices to mitigate known vulnerabilities and reduce the attack surface.



