CVE-2026-32843EPSS p44.8%
CVE-2026-32843CVE-2026-32843
Description
Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
Scoring
| EPSS | 0.56% probability of exploitation · percentile 44.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-14 |