Hereta's vulnerability profile is concentrated in a specialized industrial networking device, the ETH-IMC408M, where disclosures center on web-interface input handling and session-management issues including cross-site scripting and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hereta over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29520MEDIUM Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute | Mar 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-29513MEDIUM Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by manip | Mar 16, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-29510MEDIUM Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by manip | Mar 16, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-29521MEDIUM Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing C | Mar 16, 2026 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hereta.
Media articles that mention a CVE ID that affects a product developed by Hereta — matched by CVE ID, not by vendor name.