Description
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via cross‑site scripting in device web interface
Action: Apply Patch
AI Analysis

Impact

A reflected or stored cross‑site scripting flaw in Contec CONPROSYS PAC Series devices allows an attacker to inject and execute arbitrary scripts in the web browser of a user who is logged into the device’s interface. The vulnerability is a classic CWE‑79 XSS weakness that can lead to session hijacking, data theft, or interface defacement. The impact is limited to the authenticated web session of the user who loads the compromised page.

Affected Systems

Contec Co., Ltd. products affected are the Configurable type CPS‑PCS341[][]‑DS1‑1201 and the Integrated Type CPS‑PC341[][]‑*-9201. No specific firmware or software version numbers are listed, but the vulnerability applies to the current releases of these device families mentioned in the vendor advisory.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium‑severity flaw, and the EPSS score is not available, so the current likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog. Attackers likely exploit it by sending a crafted HTTP request to the device’s web UI while an authenticated user is browsing the interface; the flaw does not require local privileges and can be triggered remotely over the network.

Generated by OpenCVE AI on September 14, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest security patch for the affected Contec device from the vendor website.
  • Ensure that only authorized users can access the device’s web interface and consider disabling the web UI on networks where it is not required.
  • As an interim measure, restrict the user’s permissions to limit the ability to create or edit configuration pages that can contain script tags, and apply input validation or output encoding to mitigate the XSS risk until the patch is applied.

Generated by OpenCVE AI on September 14, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Contec CONPROSYS PAC Series Enables Arbitrary Script Execution on Authenticated Users

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:48.708Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82776

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:19.527Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:19.113

Modified: 2026-09-14T12:17:47.847

Link: CVE-2026-82776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T10:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')