Description
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Execution of arbitrary scripts by authenticated users via cross‑site scripting
Action: Immediate Patch
AI Analysis

Impact

A cross‑site scripting flaw in the web interface of Contec’s CONPROSYS M2M Gateway and Controller product lines allows an attacker to inject and run arbitrary JavaScript in the browser of a logged‑in user. The vulnerability is a classic client‑side injection (CWE‑79) that can be abused to hijack sessions, exfiltrate credentials, or perform further malicious actions from the victim’s machine.

Affected Systems

The flaw affects Contec Co., Ltd. devices of the M2M Controller configurable type CPS‑MCS341*, integrated type CPS‑MC341, as well as the M2M Gateway configurable type CPS‑MGS341* and integrated type CPS‑MG341*. These models provide web‑based management interfaces that are susceptible to the script injection.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium level of risk, and the EPSS score is < 1%, suggesting limited known activity. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be authenticated to the device’s web interface, implying that an attacker could trick a legitimate user or compromise the device’s credentials to inject malicious code. Given the potential for data theft and compromise of downstream systems, patching or mitigating the issue is strongly advised.

Generated by OpenCVE AI on September 14, 2026 at 21:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Contec’s latest security update for the affected M2M Controller and Gateway models per the vendor’s release notes.
  • If a patch is unavailable, deny external access to the device’s web management interface and enforce multi‑factor authentication for any remaining users.
  • Review and tighten input validation on the web interface, ensuring that script tags are properly escaped or stripped from user‑supplied data.

Generated by OpenCVE AI on September 14, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Cross‑site Scripting Vulnerability in CONPROSYS M2M Gateway and Controller Web Interfaces

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:49.220Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82773

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:25.772Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:18.690

Modified: 2026-09-14T12:17:47.487

Link: CVE-2026-82773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T21:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')