PSIRT-144: GridTime™ 3000 GNSS Time Server CSRF to XSS
Vulnerability Details
Cross-Site Scripting (XSS) Vulnerability on Several Endpoints by Utilizing Cross-Site Request Forgery (CSRF) in GridTime™ 3000 GNSS Time Server
Improper neutralization of input during POST requests on several API endpoints in the GridTime 3000 allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.
CWE-79
Date of Disclosure: 06/10/2026
Affected Product:GridTime™ 3000 GNSS Time Server
Vulnerability Type: CSRF XSS vulnerability
CVE Identifier: CVE-2026-12619
CVSS Score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A
CVSS 4.0 Score: 5.1 / Medium
Vulnerability Description:
The GridTime 3000 GNSS Time Server has a XSS vulnerability on several API endpoints that can be triggered via a CSRF
{"SalesForceSecurePath":"https://microchip.my.salesforce-scrt.com","EmbeddedServiceName":"Messaging_For_Microchip","SalesForcePath":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924","AgentAvailableHeader":"No problem. Chat with our engineering experts or schedule a call that's convenient for you.","ScheduleCallUrl":"https://microchip.my.site.com/schedulemeetingportal/s/","SalesforceOrgId":"00Do0000000KAkK","JsUrl":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924/assets/js/bootstrap.min.js"}