Vulnerabilities in Digi PortServer TS and Digi One SP IA

Vulnerabilities in Digi PortServer TS and One SP IA: authentication bypass and XSS. Upgrade to Digi Connect EZ to avoid exposures.

miércoles, 8 de julio de 2026 • 2 min read • Q2BSTUDIO Team

How to protect your Digi devices from authentication attacks and XSS

Critical vulnerabilities have recently been disclosed affecting Digi PortServer TS and Digi One SP IA devices, widely used in industrial control and M2M communication environments. These security flaws allow an unauthenticated attacker to bypass authentication mechanisms and access restricted resources, as well as execute persistent malicious scripts through web panel configuration fields, compromising system confidentiality and integrity. The severity of these vulnerabilities, classified with CVSS scores of up to 8.2 in version 4.0, underscores the need to adopt robust cybersecurity measures across the entire operational technology infrastructure. The critical manufacturing, communications, transportation, and information technology sectors are the most exposed, as these devices often manage network interfaces and sensitive data. In response, manufacturers recommend updating to newer versions or migrating to products such as Digi Connect EZ, but while the transition is underway, it is vital to implement compensating controls: enable HTTPS, disable the web server when not required, segment networks, and restrict access via firewalls or VPNs. Secure management of administrative passwords is also essential, as some exploits require prior authentication to inject malicious code. This scenario highlights the importance of a comprehensive security approach that combines good configuration practices, staff training, and advanced technological solutions. In this context, companies like Q2BSTUDIO offer custom application development and bespoke software services that integrate security controls from the design phase. Additionally, their cybersecurity services help identify vulnerabilities through penetration testing and risk analysis, ensuring that exposed systems meet the most demanding standards. Artificial intelligence also plays a growing role in early threat detection: AI agents can monitor anomalous patterns in industrial networks and trigger automatic responses. Similarly, the use of AWS and Azure cloud services provides scalable environments with managed security layers, ideal for hosting device management platforms. For business areas, business intelligence and Power BI services facilitate the visualization of security indicators and device performance, enabling informed decisions. Ultimately, the combination of robust software, modern cybersecurity protocols, and the adoption of AI for businesses constitutes the best strategy to mitigate risks such as those described in this alert. To delve deeper into how to protect your infrastructure, we recommend consulting the specialized cybersecurity and pentesting services offered by Q2BSTUDIO, which address both prevention and incident response.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.