PSIRT-147: GridTime™ 3000 GNSS Time Server Open Redirect
Vulnerability Details
Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GNSS Time Server
An open redirect vulnerability in the GridTime 3000 (password reset form) allows redirection of an arbitrary URL when submitting the password change form, allowing for redirection to an uncontrolled URL. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.
CWE-601
Date of Disclosure: 06/10/2026
Affected Product:GridTime 3000 GNSS Time Server
Vulnerability Type: Open redirectUrl parameter
CVE Identifier: CVE-2026-12622
CVSS Score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS 4.0 Score: 5.3 / Medium
Vulnerability Description:
The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission
{"SalesForceSecurePath":"https://microchip.my.salesforce-scrt.com","EmbeddedServiceName":"Messaging_For_Microchip","SalesForcePath":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924","AgentAvailableHeader":"No problem. Chat with our engineering experts or schedule a call that's convenient for you.","ScheduleCallUrl":"https://microchip.my.site.com/schedulemeetingportal/s/","SalesforceOrgId":"00Do0000000KAkK","JsUrl":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924/assets/js/bootstrap.min.js"}