This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade GridTime 3000 GNSS Time Server to the latest firmware. As of the firmware release 1.2r0.0, Access tokens have been removed from URL parameters on affected endpoints.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microchip
Microchip gridtime 3000 |
|
| Vendors & Products |
Microchip
Microchip gridtime 3000 |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. | |
| Title | Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Microchip
Published:
Updated: 2026-06-29T05:22:09.732Z
Reserved: 2026-06-18T14:15:03.036Z
Link: CVE-2026-12620
Updated: 2026-06-22T16:52:53.157Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:35:30Z