PT-2026-103625 · Aja · Helo Plus
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AJA HELO Plus versions prior to 2.1.7
Description
A stored cross-site scripting issue exists that allows unauthenticated attackers with network access to inject malicious JavaScript. This occurs when the
eParamID SystemName variable is set with unsanitized data via the '/config?action=set' API endpoint. If device authentication is disabled, the injected script executes persistently in the browser of any administrator accessing the web management interface. This can lead to the theft of stored secrets, including web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, or the hijacking of authenticated sessions.Recommendations
Update AJA HELO Plus to version 2.1.7 or later.
Enable device authentication to prevent unauthenticated access to the configuration API.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helo Plus