Impact
A cross‑site scripting flaw in the web interface of Contec FX series devices allows an attacker to inject malicious JavaScript into a page viewed by a logged‑in user. The injected script runs with the privileges of that user’s browser session, potentially stealing session cookies, manipulating the UI, or performing unauthorized actions within the device. This weakness is classified as CWE‑79.
Affected Systems
Contec Co., Ltd. FXA3000, FXA3020, FXA3200, FXA5000, FXA5020, FXE3000, FXE3000‑WP, FXE4000, FXE4000‑WP, FXE5000, FXS300‑CN, FXS4000, FXS4020, FXS5000, and FXS5021 are all affected, including all variants with supplementary identifiers. Refer to the vendor’s security bulletin linked in the references for details on which firmware revisions contain the fix; all units in these series should be verified and updated to the latest firmware revision.
Risk and Exploitability
The CVSS base score of 4.8 indicates moderate severity, while an EPSS score of less than 1% shows that exploitation is unlikely at present. The flaw operates only within the client’s browser; an attacker must lure a logged‑in user to a crafted page or trigger the malicious script through social engineering or a direct link. The vulnerability is not listed in the CISA KEV catalog, so no widespread public exploitation has been reported.
OpenCVE Enrichment