CVE-2026-23819
EUVD-2026-2973412.05.2026, 19:16
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.
Awaiting analysis
This vulnerability is currently awaiting analysis.