Impact
A Cross‑Site Scripting vulnerability (CWE‑79) exists in the web interface of Contec RP‑WA H‑SR Series devices. When exploited, an attacker can inject and execute arbitrary client‑side scripts in the browser of a logged‑in user. This capability may allow theft of session cookies, exposure of confidential data, or manipulation of the web page content delivered by the device.
Affected Systems
Contec Co., Ltd. RP‑WA H‑SR1, RP‑WA H‑SR12, RP‑WA H‑SR2, RP‑WA H‑SR22. Specific firmware or version numbers are not disclosed in the available data.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote, through the device’s web interface, and requires that the target user be authenticated and logged in. Given the absence of a known exploit but the potential for client‑side code execution, the risk is moderate and primarily concerns confidentiality and integrity of data stored or processed by the affected device.
OpenCVE Enrichment