Blog HackRTU

 

Aprende sobre vulnerabilidades, información técnica con una perspectiva diferente y estate a la última de todos los movimientos de HackRTU

 

Descubre los últimos artículos sobre ciberseguridad industrial, vulnerabilidades OT, análisis de dispositivos, investigaciones técnicas, 0‑days y noticias relevantes del sector. En el blog de HackRTU profundizamos en la seguridad de sistemas industriales, en la familia de estándares IEC 62443 y tendencias e investigación en el ámbito de la ciberseguridad industrial.

 

CVE-2026-27867 affecting REGESTA SMART HD-PLC FROM TELDAT

 

ADVISORY HRTU#0004

 

 

The HackRTU CNA has coordinated the new vulnerability CVE-2026-27867, from medium severity, in the Regesta Smart HD-PLC - TLDPH16D2 industrial router device of Teldat. These vulnerabilities have been discovered by Aarón Flecha Menéndez and Víctor Bello Cuevas.

 

DETAILS OF THE AFFECTED SOLUTION:

  • Provider: Teldat
  • Specific model: Regesta Smart HD-PLC - TLDPH16D2
  • Affected firmware version: 11.02.06.00.02

 

SPECIFIC INFORMATION OF THE 0-DAY VULNERABILITY:

The vulnerability has been assigned the following codes, CVSS v4.0 base score, CVSS vector, CWE and CAPEC vulnerability type for each vulnerability:

  • CVE-2026-27867: CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT

    • CVSS v4.0: 4,8 (Medium)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
    • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
    • CAPEC-242 Code Injection
      • CAPEC-63 Cross-Site Scripting (XSS)
    • CPE 2.3 Applicability:
      • cpe:2.3:a:teldat:regesta_smart_hd-plc_-_tldph16d2:11.02.06.00.02:*:*:*:*:*:*:*
    • EPSS: **As soon as possible**
    • EUVD: **As soon as possible**

 

CVE DESCRIPTION

To carry out this attack, the device’s ‘Reset’ functionality within the /upgrade/index.html panel was exploited. By using the ‘cmdcookie’ parameter, it was possible to inject a specific payload to embed a malicious script (Cross-site Scripting (XSS)). The following URL is where the vulnerability was exploited: https://172.16.6.102/upgrade/index.html

This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.06.00.02

 

SOLUTIONS, MITIGATIONS AND INFORMATION:

The provider has implemented the new version 11.02.06.00.03 which solves the security problems detected in the affected version. The end user has to download the new version in the Teldat - Client Support Portal and implement it in the device (https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US).

 

REFERENCES:

Specific links related to the notice:

 

 

HACKRTU TEAM