« Volver al listado

CVE-2026-48999

Estado: AplazadaMedia (5.7)—

Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user cookies, hijack session privileges, and tamper with page content.Since the malicious code is stored within the system, the attack scope is broad and the concealment is strong, making it frequently employed for data theft attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48999",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48999",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-27T17:59:17.806895Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@zte.com.cn",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@zte.com.cn",
      "affectedData": [
        {
          "vendor": "ZTE",
          "product": "ZXUniPOS NDS-LTE",
          "versions": [
            {
              "status": "affected",
              "version": "Versions < V24.40.40CP01 (excluding V24.30.40CP03, V24.40.40CP01)"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-27T04:16:31.463",
  "references": [
    {
      "url": "https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/2811026568490730190",
      "source": "psirt@zte.com.cn"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@zte.com.cn",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user cookies, hijack session privileges, and tamper with page content.Since the malicious code is stored within the system, the attack scope is broad and the concealment is strong, making it frequently employed for data theft attacks."
    },
    {
      "lang": "es",
      "value": "Los atacantes elaboran cuidadosamente scripts maliciosos, como JavaScript, y los inyectan en sistemas objetivo; cuando otros usuarios acceden a páginas que contienen dicho contenido malicioso, los scripts se cargan y ejecutan automáticamente en el navegador de la víctima. Los atacantes pueden así robar cookies de usuario, secuestrar privilegios de sesión y manipular el contenido de la página. Dado que el código malicioso se almacena dentro del sistema, el alcance del ataque es amplio y la ocultación es fuerte, lo que lo convierte en un método frecuentemente empleado para ataques de robo de datos."
    }
  ],
  "lastModified": "2026-07-24T12:10:00.210",
  "sourceIdentifier": "psirt@zte.com.cn"
}