CVE-2026-32963 Details
Description
SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser.
A reflected cross-site scripting vulnerability has been identified in the SD-330AC device and the AMC Manager application, both provided by Silex Technology, Inc. This vulnerability affects SD-330AC versions through 1.42 and AMC Manager versions through 5.0.2. When a user logs into the affected device and accesses a crafted web page, it may allow for the execution of arbitrary scripts in the user's browser.
Users are advised to update to SD-330AC firmware version 1.50 or later and AMC Manager version 5.1.0 or later. After updating, it is recommended to set an administrator password for the web configuration interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU94271449/ | [email protected] | Third Party Advisory |
| https://www.silex.jp/support/security-advisories/2026-001 | [email protected] | Vendor Advisory |
| https://www.silex.jp/support/security-advisories/en/2026-001 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| silextechnology sd-330ac firmware | < 1.50 |
CPE
Remediation
| |
| silextechnology sd-330ac | All versions |
CPE
Remediation
| |
| silextechnology amc manager | < 5.1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | New CVE Received | [email protected] |