Digi Fixes Ethernet Device Servers
According to a CISA report, Digi International has an upgrade for vulnerabilities in its PortServer TS and Digi One SP IA device servers. Issues include auth bypass (CVE-2026-12352, CVSS 5.9 V3, 8.2 V4) and stored XSS in web management (CVE-2026-12948, CVSS 3.8 V3, 4.8 V4). Digi recommends upgrading to Digi Connect EZ/TS and interim mitigations like disabling web servers or enabling HTTPS.
How this was made

The 30-second read
Why it matters
The report describes two issues: an auth-bypass vulnerability (CVE-2026-12352) and a stored XSS issue in the web management interface (CVE-2026-12948), with mitigations including disabling the web server or enabling HTTPS and restricting admin access.
Market read
Traders get a concrete security-risk catalyst for DGII’s connected-device hardware, but the article provides no financial guidance or evidence of active exploitation.
What to watch
Customer remediation timelines, whether affected models are still widely deployed, and whether DGII’s recommended upgrade (Digi Connect EZ/EZ TS) is readily available could drive real-world risk more than the disclosure itself.
Background
Digi International’s PortServer TS and Digi One SP IA are serial-to-Ethernet device servers used for remote management of legacy industrial equipment.
Ticker impact
CISA-linked report says Digi International’s PortServer TS and Digi One SP IA have auth-bypass and XSS flaws, prompting upgrade guidance.
Likely limited immediate price impact, but could raise customer churn or support costs if patches/upgrades are delayed.
The article is a vulnerability disclosure with recommended mitigations and no exploit in the wild; it is material for enterprise customers but not a direct financial print for DGII.
Market effects
Highlights ongoing cybersecurity risk in industrial/IoT connectivity hardware and may increase scrutiny of device management interfaces.
No specific regional demand or regulatory action beyond CISA reference.
Advisory applies globally to deployments in manufacturing, transportation, and IT where these device servers are used.
Counterpoint
Because the article states no exploit is currently targeting the vulnerabilities, market impact may be muted and largely confined to IT/security teams.
Key entities
- companyDigi International
Subject of the advisory, with affected PortServer TS and Digi One SP IA product lines and upgrade recommendations.
- regulatorCISA
Referenced in the report as the source context for the vulnerability disclosure.
- vulnerabilityCVE-2026-12352
Authentication bypass and access to restricted resources vulnerability, CVSS V3 base 5.9 (V4 8.2).
- vulnerabilityCVE-2026-12948
Stored XSS in web management interface, CVSS V3 base 3.8 (V4 4.8).


