Description
Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting in web interface
Action: Apply patch
AI Analysis

Impact

A cross‑site scripting (XSS) flaw in CONPROSYS nano Series allows an attacker to inject and run arbitrary client‑side scripts within the browsers of authenticated users. This could lead to session hijacking, credential theft, or execution of malicious actions on behalf of the logged‑in user. The weakness is a classic client‑side injection problem (CWE‑79).

Affected Systems

Contec Co., Ltd. products including the Programmable Remote I/O Coupler Unit (‑S1‑041, the Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN‑EOB471EI‑[]1, and the Remote I/O Coupler Unit (Server Type) CPSN‑MCB271‑*. No specific firmware or software revision numbers are listed beyond these model identifiers.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, though the Exact Public Score Scale (EPSS) is not available, suggesting limited data on exploitation likelihood. The flaw is not listed in the CISA KEV catalog, so no known active exploitation campaigns are documented. The likely attack vector requires the attacker to have access to the device’s web management interface, typically through an authenticated session. Because the vulnerability is confined to the user’s browser, it affects confidentiality and integrity of user data and can lead to privilege escalation if the attacker can execute scripts that alter stored settings or trigger privileged operations.

Generated by OpenCVE AI on September 14, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Contec security update detailed in the vendor’s security advisory (PDF link provided in the references).
  • Verify that the affected firmware or software versions are no longer in use on all deployed units.
  • Implement input validation and output encoding on the web interface, and consider enforcing a content security policy to restrict inline script execution.
  • Limit external access to the device’s management interface by firewall rules or VPN, ensuring only trusted administrators can reach the web console.

Generated by OpenCVE AI on September 14, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.815Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82781

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:09.355Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:19.803

Modified: 2026-09-14T12:17:48.450

Link: CVE-2026-82781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T10:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')