Description
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary script execution by authenticated users via cross‑site scripting
Action: Immediate Patch
AI Analysis

Impact

A cross‑site scripting flaw exists in the web interface of Contec’s CONPROSYS M2M devices, allowing a malicious script to run inside the browser of a logged‑in user. This injects code that can hijack the user’s session, exfiltrate credentials, or further compromise the device that the victim is already authenticated to. The weakness is a classic client‑side injection (CWE‑79).

Affected Systems

The vulnerability affects Contec Co., Ltd. devices of the M2M Controller configurable type CPS‑MCS341*, integrated type CPS‑MC341, and the M2M Gateway configurable type CPS‑MGS341* and integrated type CPS‑MG341*. These models provide web‑based management interfaces that are susceptible to script injection. No specific version information is disclosed.

Risk and Exploitability

Based on the description, it is inferred that an attacker must be authenticated to the device’s web interface to inject the malicious code. The CVSS score of 5.1 indicates a medium severity, while the EPSS score of < 1% suggests limited current exploitation activity. The vulnerability is not listed in the CISA KEV catalog. Even with low exploitation probability, the potential for data theft and downstream compromise makes patching or mitigation strongly recommended.

Generated by OpenCVE AI on September 15, 2026 at 16:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Contec security update for the affected M2M Controller and Gateway models as detailed in the vendor’s release notes.
  • If a patch is not currently available, restrict external access to the device’s web management interface and enforce multi‑factor authentication for all remaining users.
  • Verify that input validation on the web interface sanitizes or removes script tags from user‑supplied data to prevent future injection.

Generated by OpenCVE AI on September 15, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec m2m Controller Configurable Type Cps-mcs341*
Contec m2m Controller Integrated Type Cps-mc341
Contec m2m Gateway Configurable Type Cps-mgs341*
Contec m2m Gateway Integrated Type Cps-mg341*
Vendors & Products Contec
Contec m2m Controller Configurable Type Cps-mcs341*
Contec m2m Controller Integrated Type Cps-mc341
Contec m2m Gateway Configurable Type Cps-mgs341*
Contec m2m Gateway Integrated Type Cps-mg341*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Cross‑site Scripting Vulnerability in CONPROSYS M2M Gateway and Controller Web Interfaces

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Cross‑site Scripting Vulnerability in CONPROSYS M2M Gateway and Controller Web Interfaces

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Contec M2m Controller Configurable Type Cps-mcs341* M2m Controller Integrated Type Cps-mc341 M2m Gateway Configurable Type Cps-mgs341* M2m Gateway Integrated Type Cps-mg341*
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:49.220Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82773

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:25.772Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:18.690

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')