Impact
The vulnerability is a cross‑site request forgery (CWE‑352) that allows an attacker to trick an authenticated user into performing unintended actions on the device’s web interface. By presenting a specially crafted page, the attacker can cause the browser to submit POST or GET requests with the victim’s session credentials, leading to unauthorized configuration changes or other state‑altering operations.
Affected Systems
Contec Co., Ltd. devices across many product lines—ECE1000, ECE1020, ECS1020, FXA3000, FXA3000‑[][], FXA3020, FXA3020‑[][], FXA3200, FXA5000, FXA5020, FXA5020‑[][],‑WP, FXE3000‑[][], FXE4000, FXE4000‑WP, FXE5000, FXE5000‑[][], FXS300[]‑CN, FXS4000, FXS4020, FXS5000‑[][], FXS5021, PC‑HELPER Wireless I/O DIO‑0404RY‑LWF, PC‑HELPER‑LWF‑US, Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN‑PCB271‑S1‑041, RP‑WAH‑SR1, RP‑WAH‑SR12, RP‑WAH‑SR2, RP‑WAH‑SR22, Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN‑EOB471EI‑[]1, Remote I/O Coupler Unit (Server Type) CPSN‑MCB271‑*, and SGA1000.
Risk and Exploitability
The CVSS score of 5.1 classifies the flaw as moderate severity. EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the issue is not listed in CISA KEV, indicating no evidence of widespread exploitation. Because the exploit requires user interaction and a valid session, the probability of exploitation is lower than that for purely remote flaws, yet the ability to alter device state or execute commands poses a significant risk to device integrity and availability.
OpenCVE Enrichment