PT-2026-103625 · Aja · Helo Plus

·

CVE-2026-47096

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AJA HELO Plus versions prior to 2.1.7
Description A stored cross-site scripting issue exists that allows unauthenticated attackers with network access to inject malicious JavaScript. This occurs when the eParamID SystemName variable is set with unsanitized data via the '/config?action=set' API endpoint. If device authentication is disabled, the injected script executes persistently in the browser of any administrator accessing the web management interface. This can lead to the theft of stored secrets, including web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, or the hijacking of authenticated sessions.
Recommendations Update AJA HELO Plus to version 2.1.7 or later. Enable device authentication to prevent unauthenticated access to the configuration API.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47096

Affected Products

Helo Plus