Impact
A cross‑site scripting flaw exists in the web interface of Contec’s CONPROSYS M2M devices, allowing a malicious script to run inside the browser of a logged‑in user. This injects code that can hijack the user’s session, exfiltrate credentials, or further compromise the device that the victim is already authenticated to. The weakness is a classic client‑side injection (CWE‑79).
Affected Systems
The vulnerability affects Contec Co., Ltd. devices of the M2M Controller configurable type CPS‑MCS341*, integrated type CPS‑MC341, and the M2M Gateway configurable type CPS‑MGS341* and integrated type CPS‑MG341*. These models provide web‑based management interfaces that are susceptible to script injection. No specific version information is disclosed.
Risk and Exploitability
Based on the description, it is inferred that an attacker must be authenticated to the device’s web interface to inject the malicious code. The CVSS score of 5.1 indicates a medium severity, while the EPSS score of < 1% suggests limited current exploitation activity. The vulnerability is not listed in the CISA KEV catalog. Even with low exploitation probability, the potential for data theft and downstream compromise makes patching or mitigation strongly recommended.
OpenCVE Enrichment