BRIEFING NOTE: CVE-2026-32963 SD-330AC and AMC Manager devices manufactured by Silex Technology, Inc. contain a reflected cross-site scripting (XSS) vulnerability that allows arbitrary script execution in a user's browser when they visit a crafted web page after logging into the affected device. The vulnerability requires user interaction and is network-accessible without authentication, making it a phishing or social engineering attack vector. The vulnerability carries a CVSS score of 6.1 (MEDIUM severity) with an attack vector that is network-based, requires low complexity, and necessitates user interaction. The attack can affect confidentiality and integrity across security boundaries through session hijacking or credential theft, though availability is not impacted. The FAUCET Risk Score of 34.0 out of 100 indicates a moderate overall risk profile. Currently, there is no evidence of active exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, the Hot List is inactive, and the EPSS score of 0.0003 indicates minimal probability of exploitation in the wild. Community attention appears limited at this time, and no public exploit code has been identified, suggesting this remains a low-priority threat requiring standard patching procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.