Impact
A cross‑site scripting flaw exists1000 web interface. The vulnerability permits an attacker to inject malicious JavaScript that runs in the browser of any authenticated user. Because the script executes with the privileges of the logged‑in session, an attacker could hijack the session, steal credentials, or perform other actions within that user’s scope.
Affected Systems
Contec Co., Ltd. SGA1000. No specific affected versions are listed.
Risk and Exploitability
The flaw has a CVSS score of 4.8, indicating moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to be user‑controlled input fields or malicious links that an authenticated user interacts with, requiring the victim to be logged into the device’s web console at the time the script executes.
OpenCVE Enrichment