Security Advisory HELO Plus Web Interface and Diagnostics Export Vulnerabilities

  • Advisory ID: AJA-SA-2026-003
  • Publish Date: September 30, 2026
  • Severity: High
  • CVSS v3.1 Score: 7.5 / 10
  • Status: Resolved. HELO Plus fixed in firmware v2.1.7

Summary

AJA has resolved two reported security vulnerabilities in HELO Plus firmware prior to v2.1.7.

CVE Title
CVE-2026-47096 Stored XSS via System Name Parameter
CVE-2026-47097 Hardcoded AES Passphrase for Diagnostics Export Bundle

These vulnerabilities affect the following AJA products:

Product Affected Versions Status
HELO Plus Firmware prior to v2.1.7 Fixed in firmware v2.1.7

AJA is not aware of any reports that these vulnerabilities have been actively exploited. A fix is available in HELO Plus firmware v2.1.7, and AJA strongly recommends updating all affected devices.

Credits

AJA thanks the following researchers for reporting these vulnerabilities:

  • Saleh Alghamdi
  • Abdulrahman Aldossary

Recommended Immediate Mitigations

Until a device is running firmware v2.1.7, apply these mitigations to reduce exposure:

  • Disable UPnP Host under System Settings. This partially mitigates CVE-2026-47096.
  • Treat diagnostics bundles exported from firmware prior to v2.1.7 as readable by anyone who obtains them, and share them only over trusted channels. This addresses CVE-2026-47097.

These mitigations reduce risk but do not eliminate it. Updating to firmware v2.1.7 remains the only complete remediation.

AJA Remediation Status

HELO Plus - Fixed

HELO Plus firmware v2.1.7 resolves both CVEs. All HELO Plus units running firmware prior to v2.1.7 are affected, and AJA strongly recommends updating.

Firmware v2.1.7 is available on the HELO Plus v2.1.7 download page, or from the Support tab of the HELO Plus product page. See the v2.1.7 release notes for full details.

References

Revision History

Date Change
September 30, 2026 Initial publication.

Contact

For questions regarding this advisory or assistance with mitigation, contact security@aja.com.

This advisory will be updated as new information becomes available.