CVE-2026-27870 Details
Description
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS) payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.
A cross-site scripting (XSS) vulnerability has been identified in the Teldat Regesta Smart HD-PLC router, model TLDPH16D2, running firmware version 11.02.05.10.02. The vulnerability allows an attacker with network access and a registered account to inject arbitrary JavaScript by placing an XSS payload in the 'Hostname' field of the configuration file. This injection is then executed in the path '/upgrade/query.php?cmd=p+3%3Bversion'.
Users can update to version 11.02.06.00.02, available on the Teldat Client Support Portal, to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2026CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.teldat.com/images/content/docs/Teldat_dm1087_regesta_smart_nessum_series_installation(1).pdf | HackRTU | |
| https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US | HackRTU | Vendor |
| https://www.hackrtu.com/blog/CNA-CVE-2026-27870/ | HackRTU | AdvisoryRemedy |
| https://www.hackrtu.com/blog/CNA-HRTU-0003/ | HackRTU | |
| https://www.teldat.com/es/ | HackRTU | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | HackRTU |
Affected Products
| Product | Versions |
|---|---|
| Teldat Regesta Smart HD-PLC | 11.02.05.10.02 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | HackRTU |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | HackRTU |
Volerion