Description
Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting in device web interface
Action: Apply patch
AI Analysis

Impact

A client‑side injection weakness (CWE‑79) exists in the web interface of the CONPROSYS nano Series. In practice, a user who is logged into the device can be tricked into executing an arbitrary script that was supplied by an attacker. This can lead to theft of session information or to the attacker performing authenticated actions on behalf of the victim.

Affected Systems

Contec Co., Ltd. products including the Programmable Remote I/O Coupler Unit (‑S1‑041), the Remote I/O Coupler Unit (EtherNet/IP Adapter, CPSN‑EOB471EI‑[]1), and the Remote I/O Coupler Unit (Server Type, CPSN‑MCB271‑*). Firmware revisions are not specified, but any unit running the CONPROSYS nano Series software is potentially impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score is below 1 % suggesting limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no known active exploitation campaigns exist. Based on the description, the management interface and then trick an authenticated user into processing malicious input. If successfully exploited, the attacker could compromise the confidentiality and integrity of a logged‑in session and carry out substrate actions on the device.

Generated by OpenCVE AI on September 15, 2026 at 15:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and apply the vendor‑released security update documented in the Contec advisory PDF available at the provided URL.
  • Deploy the patch on all units running the CONPROSYS nano Series firmware to eliminate the XSS flaw.
  • Limit access to the device’s web interface by restricting it to trusted administrators, for example via firewall rules or VPN access.
  • If a patch is not yet available, enforce a strict content‑security‑policy on the web console to mitigate the impact of potential client‑side injection attacks.

Generated by OpenCVE AI on September 15, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041
Contec remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1
Contec remote I/o Coupler Unit (server Type) Cpsn-mcb271-*
Vendors & Products Contec
Contec programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041
Contec remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1
Contec remote I/o Coupler Unit (server Type) Cpsn-mcb271-*

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Cross‑site scripting enabling arbitrary script execution in Contec CONPROSYS device web interface

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Cross‑site scripting enabling arbitrary script execution in Contec CONPROSYS device web interface

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Contec Programmable Remote I/o Coupler Unit (software Plc Type) Cpsn-pcb271-s1-041 Remote I/o Coupler Unit (ethernet/ip Adapter) Cpsn-eob471ei-[]1 Remote I/o Coupler Unit (server Type) Cpsn-mcb271-*
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.815Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82781

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:09.355Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:19.803

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')