
Attackers exploited authentication bypass (CVE-2025-3659) in Digi PortServer devices to inject malicious scripts via stored XSS, enabling credential theft and persistent access. Runtime segmentation helps contain such post-compromise activity across industrial networks. #DevSecOps 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/digi-international-portserver-ts-digi-one-sp-ia-vulnerabilities-2026
Post summary
Attackers exploited CVE‑2025‑3659 on Digi PortServer devices, using a stored XSS vulnerability to inject malicious scripts that facilitate credential theft and persistent access, with no patch or mitigation mentioned.

