CVE-2026-52232
Received Received - Intake

Reflected XSS in FS Inc S3150-8T2F Switch

Vulnerability report for CVE-2026-52232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: MITRE

Description

A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fs_inc s3150-8t2f_switch 2.2.0d

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch version 2.2.0D Build 118101. It allows attackers to inject and execute arbitrary JavaScript code in the victim's browser by tricking them into clicking a specially crafted URL.

Detection Guidance

To detect this reflected XSS vulnerability in FS Inc S3150-8T2F Switch 2.2.0D Build 118101, inspect web traffic for requests to /logo.asp with suspicious parameters. Check server logs for unusual URL patterns containing JavaScript code. Manually test by sending crafted URLs to the /logo.asp endpoint and observing if JavaScript executes in the browser.

Impact Analysis

An attacker could steal sensitive information like session cookies, login credentials, or other personal data from users who access the vulnerable switch interface. They might also perform actions on behalf of the user or redirect them to malicious sites.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other standards as it is a reflected XSS issue in a network switch interface. However, if exploited, it could lead to unauthorized access or data exfiltration, which may violate data protection requirements under these regulations depending on the context of use.

Mitigation Strategies

Immediately update the FS Inc S3150-8T2F Switch firmware to the latest version to patch the /logo.asp XSS vulnerability. If an update is unavailable, restrict access to the /logo.asp endpoint via network firewall rules or disable it if not required. Implement input validation and output encoding on the switch's web interface to prevent XSS attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart