CVE-2026-9144: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Taiko Network Communications Pte Ltd. AG1000-01A SMS Alert Gateway
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields. Attackers can bypass front-end length restrictions using JavaScript comments and template literals to concatenate executable script fragments that are rendered in administrative dashboard views such as index.zhtml, resulting in persistent script execution within administrative sessions.
AI Analysis
Technical Summary
CVE-2026-9144 is a stored cross-site scripting vulnerability (CWE-79) affecting Taiko Network Communications Pte Ltd.'s AG1000-01A SMS Alert Gateway version 7.3. The vulnerability exists in the embedded web configuration interface, where authenticated attackers can fragment malicious JavaScript payloads across multiple administrative form fields. By using JavaScript comments and template literals, attackers bypass front-end length restrictions and concatenate executable script fragments. These scripts are rendered persistently in administrative dashboard views such as index.zhtml, enabling persistent script execution within administrative sessions.
Potential Impact
Successful exploitation allows authenticated attackers to execute arbitrary JavaScript persistently within the administrative interface. This can lead to session hijacking, unauthorized actions within the administrative dashboard, and potential compromise of the device's management interface. The CVSS v3.1 score of 7.6 reflects high impact on confidentiality and integrity, with low impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrative access to trusted users only and monitor for suspicious activity. Avoid using version 7.3 in production environments if possible.
CVE-2026-9144: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Taiko Network Communications Pte Ltd. AG1000-01A SMS Alert Gateway
Description
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields. Attackers can bypass front-end length restrictions using JavaScript comments and template literals to concatenate executable script fragments that are rendered in administrative dashboard views such as index.zhtml, resulting in persistent script execution within administrative sessions.
CVSS v3.1
Score 7.6high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-9144 is a stored cross-site scripting vulnerability (CWE-79) affecting Taiko Network Communications Pte Ltd.'s AG1000-01A SMS Alert Gateway version 7.3. The vulnerability exists in the embedded web configuration interface, where authenticated attackers can fragment malicious JavaScript payloads across multiple administrative form fields. By using JavaScript comments and template literals, attackers bypass front-end length restrictions and concatenate executable script fragments. These scripts are rendered persistently in administrative dashboard views such as index.zhtml, enabling persistent script execution within administrative sessions.
Potential Impact
Successful exploitation allows authenticated attackers to execute arbitrary JavaScript persistently within the administrative interface. This can lead to session hijacking, unauthorized actions within the administrative dashboard, and potential compromise of the device's management interface. The CVSS v3.1 score of 7.6 reflects high impact on confidentiality and integrity, with low impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrative access to trusted users only and monitor for suspicious activity. Avoid using version 7.3 in production environments if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-05-20T20:01:30.438Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a0e173eba1db47362a37ebd
Added to database: 05/20/2026, 20:19:10 UTC
Last enriched: 07/30/2026, 00:49:23 UTC
Last updated: 07/31/2026, 21:26:47 UTC
Views: 97
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.