Impact
A client‑side injection weakness (CWE‑79) exists in the web interface of the CONPROSYS nano Series. In practice, a user who is logged into the device can be tricked into executing an arbitrary script that was supplied by an attacker. This can lead to theft of session information or to the attacker performing authenticated actions on behalf of the victim.
Affected Systems
Contec Co., Ltd. products including the Programmable Remote I/O Coupler Unit (‑S1‑041), the Remote I/O Coupler Unit (EtherNet/IP Adapter, CPSN‑EOB471EI‑[]1), and the Remote I/O Coupler Unit (Server Type, CPSN‑MCB271‑*). Firmware revisions are not specified, but any unit running the CONPROSYS nano Series software is potentially impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is below 1 % suggesting limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no known active exploitation campaigns exist. Based on the description, the management interface and then trick an authenticated user into processing malicious input. If successfully exploited, the attacker could compromise the confidentiality and integrity of a logged‑in session and carry out substrate actions on the device.
OpenCVE Enrichment