CVE-2026-47096
Received Received - Intake

Stored XSS in AJA HELO Plus Firmware

Vulnerability report for CVE-2026-47096, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aja helo_plus to 2.1.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AJA HELO Plus firmware before 2.1.7 has a stored cross-site scripting (XSS) vulnerability. Unauthenticated attackers with network access can inject malicious JavaScript by setting an unsanitized eParamID_SystemName value via the /config?action=set web configuration API. This allows persistent script execution in the browser of any administrator accessing the web management interface.

Detection Guidance

To detect this vulnerability, check if your AJA HELO Plus device is running firmware before version 2.1.7. Use the web interface or SSH to verify the firmware version. If device authentication is disabled, inspect network traffic for unsanitized eParamID_SystemName values sent to /config?action=set.

Impact Analysis

Attackers can steal sensitive data like web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials. They can also hijack authenticated sessions, potentially gaining unauthorized access to the device and its network.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face compliance penalties and reputational damage if exploited.

Mitigation Strategies

Immediately update the AJA HELO Plus firmware to version 2.1.7 or later. Enable device authentication if it is disabled. Review and sanitize all inputs in the web configuration API, particularly eParamID_SystemName. Monitor network traffic for suspicious activity targeting the /config?action=set endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47096. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart