Medium severity5.4NVD Advisory· Published Jun 30, 2021· Updated Jun 17, 2026
CVE-2021-35956
CVE-2021-35956
Description
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:akcp:sensorprobe2_firmware:*:*:*:*:*:*:*:*Range: <sp480-20210624
- cpe:2.3:o:akcp:sensorprobe4_firmware:*:*:*:*:*:*:*:*Range: <sp480-20210624
- cpe:2.3:o:akcp:sensorprobe8-x20_firmware:*:*:*:*:*:*:*:*Range: <sp480-20210624
- cpe:2.3:o:akcp:sensorprobe8-x60_firmware:*:*:*:*:*:*:*:*Range: <sp480-20210624
- cpe:2.3:o:akcp:sensorprobe8_firmware:*:*:*:*:*:*:*:*Range: <sp480-20210624
- AKCP/sensorProbedescription
- Range: <SP480-20210624
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/163343/AKCP-sensorProbe-SPX476-Cross-Site-Scripting.htmlnvdExploitThird Party Advisory
- tbutler.org/2021/06/28/cve-2021-35956nvdExploitThird Party Advisory
- www.akcp.in.th/downloads/Firmwares/SP480-20210624.zipnvdProductVendor Advisory
- www.akcp.com/support-center/customer-login/sensor-probe-firmware-changelog/nvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.