Zucchetti Axess Access Control Devices Cross-Site Scripting Vulnerability

Vulnerability

A Cross-Site Scripting (XSS) vulnerability has been identified in the web-based configuration interface of Zucchetti Axess access control devices. This includes models XA4, X3/X3BIO, X4, X7, XIO, i-door, and i-door+. The vulnerability arises from inadequate sanitization of user input in the 'dirBrowse' parameter of the '/file_manager.cgi' endpoint. An authenticated attacker could exploit this to inject arbitrary JavaScript, executed in the context of an administrative user, potentially leading to session hijacking, unauthorized configuration changes, and disclosure of sensitive information.

Impact

Exploitation of this vulnerability could result in session hijacking, privilege escalation, and credential theft.

Reproduction

To reproduce this vulnerability, send a GET request to the '/file_manager.cgi' endpoint with the 'dirBrowse' parameter containing a script tag, such as '<script>alert(1)</script>'.

Added: Mar 18, 2026, 5:26 PM
Updated: Mar 18, 2026, 5:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
7.5
remediation
0.0
relevance
4.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.