Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iioter
Iioter iotgateway |
|
| Vendors & Products |
Iioter
Iioter iotgateway |
Mon, 11 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Cross‑Site Scripting in iotgateway Log Record Function |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 11 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Cross‑Site Scripting in iotgateway Log Record Function | |
| Weaknesses | CWE-79 |
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-11T18:51:43.783Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36906
Updated: 2026-05-11T18:51:40.147Z
Status : Deferred
Published: 2026-05-11T17:16:32.313
Modified: 2026-05-12T15:05:31.120
Link: CVE-2026-36906
No data.
OpenCVE Enrichment
Updated: 2026-05-12T09:23:32Z