CVE-2026-97871 | Zhonglun CloudPos up to 3.0.1.76 JSBridge JSBridge.cs OpenLocalBrowser url code injection

SecurityVulns

A vulnerability categorized as critical has been discovered in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to code injection.

This vulnerability is documented as CVE-2026-97871. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More