4.8
/ 10
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Description
Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If an attacking administrator configures the affected product with some malicious input, an arbitrary script may be executed on the web browser of a victim administrator who accesses the setting screen.
Basic Information
ID
CVE-2026-20894
Source
jpcert
Published
Jan 16, 2026 at 08:16
Affected Product
Vendor
TOA Corporation
Product
Multiple Network Cameras TRIFORA 3 series
Version
see the information provided by the vendor
Affected Versions
TOA Corporation Multiple Network Cameras TRIFORA 3 series see the information provided by the vendor