Digi PortServer TS and Digi One devices face auth bypass and XSS
Aging OT management interfaces leave operators fixing exposure at the network boundary while Digi points affected products toward replacement.
TL;DR
CISA issued ICSA-26-188-07 for CVE-2026-12352 and CVE-2026-12948 in Digi PortServer TS, Digi One SP, Digi One SP IA and Digi One IA devices before Firmware_2025. The advisory reaches worldwide deployments in critical manufacturing, communications, information technology and transportation systems. Digi tells PortServer TS users to enable HTTPS or disable the web server, and Digi One users to disable it or restrict access through firewall or VPN. For the stored cross-site scripting flaw, Digi says no firmware fix is coming and points operators to replacement hardware. CISA reports no known public exploitation.
CISA’s advisory puts a familiar operational technology problem in a blunt form: affected Digi management interfaces cannot be treated as ordinary web apps waiting for the next maintenance patch. CVE-2026-12352 allows an unauthenticated actor to bypass authentication and reach restricted resources on Digi PortServer TS, Digi One SP, Digi One SP IA and Digi One IA versions before Firmware_2025. The stored cross-site scripting flaw, CVE-2026-12948, requires an authenticated administrator to write affected configuration fields and then executes when another user views those pages.
The mitigation list is mostly architecture and device-lifecycle work. Digi tells PortServer TS users to enable HTTPS, or disable the web server when it is not actively needed. For Digi One SP, Digi One SP IA and Digi One IA, the instruction is starker: disable the web server, and if that cannot be done, restrict access through a firewall or VPN. Digi also says it will not provide a firmware fix for CVE-2026-12948 because the affected products are approaching end-of-life, and recommends moving to Digi Connect EZ or Digi Connect EZ TS as the long-term answer.
For critical manufacturing, communications, transportation, information technology and defense-industrial-base operators, the Monday work is inventory and exposure reduction. Find devices running affected pre-Firmware_2025 versions, confirm whether the web management interface is reachable from untrusted or public networks, limit access to trusted administrative hosts, and treat administrator credentials as part of the control boundary. CISA reports no known public exploitation, which lowers the heat. The absence of a firmware fix still leaves segmentation carrying the risk.
Published ·Deep Fathom