CVE-2026-75170
NONE—CVSS v3
—CVSS v2
0.23%
EPSS (exploit probability)
—CWE
Description
Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter.
Affected routers (0)
No routers currently mapped to this CVE in our database.