By vendor

Microchip vulnerabilities

Known CVEs affecting Microchip products, prioritized by severity, with SEC.co remediation and detection guidance.

4 published vulnerabilities

  • CVE-2026-12620MEDIUM 6.5

    GridTime 3000 GNSS Time Server contains a credential exposure vulnerability where access tokens are inadvertently leaked through URL parameters on certain endpoints. An authenticated attacker can potentially capture or intercept these tokens, gaining unauthorized access to sensitive functionality. This affects versions 1.0r0.03 through 1.1r0.0 of the firmware.

  • CVE-2026-12619MEDIUM 5.4

    Microchip GridTime 3000 contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts into web pages. When another user views the affected page, the injected script executes in their browser within the GridTime 3000 application context, potentially compromising their session, stealing credentials, or performing unauthorized actions on their behalf. The vulnerability requires an authenticated attacker and user interaction (a victim must click a link or visit a crafted page), but can affect users across different security boundaries.

  • CVE-2026-12621MEDIUM 5.4

    A cross-site scripting (XSS) vulnerability exists in the password reset form of GridTime 3000. An attacker with valid login credentials can inject malicious JavaScript code that executes in the browser of other users viewing the form, potentially stealing session cookies, credentials, or triggering unauthorized actions. The vulnerability affects versions 1.0r0.03 through 1.1.x, with the fix available in version 1.2r0.0 and later.

  • CVE-2026-12622MEDIUM 5.4

    GridTime 3000 GNSS Time Servers contain an open redirect flaw in their password change functionality. When an authenticated user submits a password change request, the application can be tricked into redirecting them to an attacker-controlled website. An attacker would need valid credentials or the ability to socially engineer a legitimate user into clicking a malicious link that contains the redirect target. While the attacker cannot directly steal data or crash the system through this flaw, they can use it to harvest credentials, distribute malware, or conduct phishing attacks by making the redirect destination appear trustworthy.