CVE-2026-32843 MEDIUM

CVE-2026-32843: Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php

Vendor Linkitonedevgroup
Product Location Aware Sensor System (LASS)
Weakness CWE-79 · XSS
Published March 19, 2026
Last update March 23, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

Description

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.

Key dates

Disclosure timeline

March 19, 2026 CVE published
March 23, 2026 Record updated