Impact
A cross‑site scripting flaw in the web interface of Contec’s CONPROSYS M2M Gateway and Controller product lines allows an attacker to inject and run arbitrary JavaScript in the browser of a logged‑in user. The vulnerability is a classic client‑side injection (CWE‑79) that can be abused to hijack sessions, exfiltrate credentials, or perform further malicious actions from the victim’s machine.
Affected Systems
The flaw affects Contec Co., Ltd. devices of the M2M Controller configurable type CPS‑MCS341*, integrated type CPS‑MC341, as well as the M2M Gateway configurable type CPS‑MGS341* and integrated type CPS‑MG341*. These models provide web‑based management interfaces that are susceptible to the script injection.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium level of risk, and the EPSS score is < 1%, suggesting limited known activity. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be authenticated to the device’s web interface, implying that an attacker could trick a legitimate user or compromise the device’s credentials to inject malicious code. Given the potential for data theft and compromise of downstream systems, patching or mitigating the issue is strongly advised.
OpenCVE Enrichment