VYPR

Gridtime 3000 Firmware

by Microchip

CVEs (4)

  • CVE-2026-12620MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

  • CVE-2026-12622MedJun 19, 2026
    risk 0.35cvss 5.4epss 0.00

    The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

  • CVE-2026-12621MedJun 19, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.

  • CVE-2026-12619MedJun 19, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.