Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hereta
Hereta eth-imc408m Hereta eth-imc408m Firmware |
|
| CPEs | cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:* cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hereta
Hereta eth-imc408m Hereta eth-imc408m Firmware |
Tue, 17 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shenzhen Hereta Technology
Shenzhen Hereta Technology hereta Eth-imc408m |
|
| Vendors & Products |
Shenzhen Hereta Technology
Shenzhen Hereta Technology hereta Eth-imc408m |
Mon, 16 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping_ipaddr parameter to compromise authenticated administrator sessions when the links are visited. | |
| Title | Hereta ETH-IMC408M Reflected XSS via ping_ipaddr Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-17T15:29:29.391Z
Reserved: 2026-03-04T15:39:26.872Z
Link: CVE-2026-29520
Updated: 2026-03-16T18:09:13.372Z
Status : Analyzed
Published: 2026-03-16T18:16:08.347
Modified: 2026-04-10T17:43:45.847
Link: CVE-2026-29520
No data.
OpenCVE Enrichment
Updated: 2026-04-13T14:28:30Z