LIVE · cybersecurity feed
Live wire
cve record

CVE-2026-32843

Published
CVSS—
Severitynone
WeaknessCWE-79
ExploitedNot in CISA KEV

Description

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32843

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32843.