CVE-2026-52232: n/a
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.
AI Analysis
Technical Summary
This vulnerability is a reflected XSS in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101. An attacker can craft a URL that causes arbitrary JavaScript execution in the victim's browser, potentially leading to information disclosure or session hijacking. The vulnerability affects a cloud-hosted service, and no known exploits are reported in the wild. The CVSS vector indicates the attack is network-based, requires no privileges, user interaction is required, and the scope is changed with low impact on confidentiality and integrity, and no impact on availability.
Potential Impact
Successful exploitation allows execution of arbitrary JavaScript in the context of the victim's browser, which can lead to limited confidentiality and integrity impacts such as theft of session tokens or manipulation of web page content. There is no impact on system availability. The vulnerability is medium severity based on CVSS 3.1 scoring.
Mitigation Recommendations
Since this is a cloud service, the vendor manages remediation server-side. A patch is available, so users should verify with the vendor that the service has been updated. No additional user action is required if the vendor has applied the patch.
CVE-2026-52232: n/a
Description
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.
CVSS v3.1
Score 6.1medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability is a reflected XSS in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101. An attacker can craft a URL that causes arbitrary JavaScript execution in the victim's browser, potentially leading to information disclosure or session hijacking. The vulnerability affects a cloud-hosted service, and no known exploits are reported in the wild. The CVSS vector indicates the attack is network-based, requires no privileges, user interaction is required, and the scope is changed with low impact on confidentiality and integrity, and no impact on availability.
Potential Impact
Successful exploitation allows execution of arbitrary JavaScript in the context of the victim's browser, which can lead to limited confidentiality and integrity impacts such as theft of session tokens or manipulation of web page content. There is no impact on system availability. The vulnerability is medium severity based on CVSS 3.1 scoring.
Mitigation Recommendations
Since this is a cloud service, the vendor manages remediation server-side. A patch is available, so users should verify with the vendor that the service has been updated. No additional user action is required if the vendor has applied the patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-08T00:00:00.000Z
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6a6d183abf32cb7a34637eb7
Added to database: 07/31/2026, 21:48:42 UTC
Last enriched: 08/08/2026, 14:29:48 UTC
Last updated: 09/14/2026, 10:01:31 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.