CVE-2026-19061
Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList data authenticity
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-345 |
| Vendor | insta |
| Product | instaknxserviceapp |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for insta instaknxserviceapp
Be the first to know when new low vulnerabilities affecting insta instaknxserviceapp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Insta / InstaKNXServiceApp
1.2.3.1469
References
Credits
๐ isZzzzz (VulDB User) VulDB CNA Team