CVE-2026-12622: Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GNSS Time Server
The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission.
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GridTime 3000 GNSS Time Server firmwareto a version that resolves this vulnerability.Fixed in 1.2r0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12622?
CVE-2026-12622 has a medium severity rating of 5.3.
How do I fix CVE-2026-12622?
To fix CVE-2026-12622, update the GridTime 3000 GNSS Time Server to a version that addresses the open redirect vulnerability.
What is the impact of CVE-2026-12622?
CVE-2026-12622 could allow attackers to redirect users to malicious sites during the password change process.
Which versions of GridTime are affected by CVE-2026-12622?
CVE-2026-12622 affects GridTime 3000 GNSS Time Server from versions 1.0r0.03 through 1.1r0.0.
When was CVE-2026-12622 published?
CVE-2026-12622 was published on June 19, 2026.