Vulnerability Details CVE-2026-12620
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.7%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-12620
-
cpe:2.3:h:microchip:gridtime_3000:-
-
cpe:2.3:o:microchip:gridtime_3000_firmware:1.0r0.03
-
cpe:2.3:o:microchip:gridtime_3000_firmware:1.0r1.0
-
cpe:2.3:o:microchip:gridtime_3000_firmware:1.1r0.0
-
cpe:2.3:o:microchip:gridtime_3000_firmware:1.1r1.0