CVE-2026-9144
7.6Taiko Network Communications Pte Ltd · AG1000-01A SMS Alert Gateway
The Taiko AG1000-01A SMS Alert Gateway is vulnerable to stored Cross-site Scripting (XSS) via the web configuration interface.
Executive summary
Taiko Network Communications AG1000-01A SMS Alert Gateway (Rev 7.3, Rev 8, UM-AG1000_R7.2) is susceptible to stored XSS, allowing attackers to execute unauthorized scripts.
Vulnerability
This vulnerability is a stored Cross-site Scripting (XSS) flaw (CWE-79) occurring in the web configuration interface. It requires low privileges and user interaction to execute malicious scripts in the context of an authenticated user's session.
Business impact
Successful exploitation allows an attacker to execute arbitrary scripts in the browser of an administrator, potentially leading to session hijacking, unauthorized configuration changes, or further compromise of the SMS gateway. Given the CVSS score of 7.6, this flaw poses a high risk to the management of secure communication infrastructure.
Remediation
Immediate Action: Monitor official vendor communication channels for a firmware update that neutralizes input within the web configuration interface.
Proactive Monitoring: Audit the web interface for any unexpected scripts or configuration changes that were not performed by authorized personnel.
Compensating Controls: Use a Web Application Firewall (WAF) to filter malicious scripts and sanitize input directed toward the SMS gateway's web configuration interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the sensitive nature of SMS alert gateways, this XSS vulnerability must be remediated promptly. Organizations should verify their current firmware version and prepare to deploy the vendor-supplied update immediately upon release to prevent unauthorized administrative control.