JVNVU#98062224
Improper restriction of XML external entity reference in XG VisionTerminal and XG-X VisionTerminal
Overview
XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references.
Products Affected
- XG-X VisionTerminal Ver.3.6.0000 and earlier
- XG VisionTerminal Ver.5.5.0010 and earlier
Description
XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation contain the following vulnerability.
- Improper restriction of XML external entity reference (CWE-611)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.7
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Base Score 5.5
- CVE-2026-82918
Impact
If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.
Solution
Update the software
Update XG-X VisionTerminal to the version above Ver.3.7.0000.
Upgrade to alternative software
The developer recommends that the users of XG VisionTerminal should upgrade to XG-X VisionTerminal Ver.3.7.0000 or above since XG VisionTerminal is EOL (end-of-life), therefore no longer supported.
Apply workaround
The developer recommends that the users should apply following workaround if applying immediate update or upgrade is difficult.
- Do not open untrusted setting files
For more information, refer to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Keyence Corporation | Vulnerability to XXE Attack Found in the XG-X VisionTerminal and the XG VisionTerminal |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Michael Heinzl reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-82918 |
| JVN iPedia |
|