CVE-2026-30695
Received
Received - Intake
Cross-Site Scripting in Zucchetti Axess Web Configuration Interface
Publication date: 2026-03-18
Last updated on: 2026-03-19
Assigner: MITRE
Description
Description
A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The vulnerability is caused by improper sanitization of user-supplied input in the dirBrowse parameter of the /file_manager.cgi endpoint.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zucchetti | axess | * |
| zucchetti | xa4 | h06_build_5522 |
| zucchetti | x3 | x02_build_4163 |
| zucchetti | xio | h06_build_5522 |
| zucchetti | idoor_plus | h06_build_5522 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |