Impact
The CPSL‑08P1EN firmware contains a cross‑site scripting flaw (CWE‑79). When a logged‑in user visits a crafted URL or submits malicious input, the device’s web interface reflects the payload without proper encoding, allowing the attacker’s JavaScript to run in the user’s browser. This enables attackers to steal session tokens, capture credentials, and potentially perform further actions in the user’s session context.
Affected Systems
Contec Co., Ltd.’s CPSL‑08P1EN device is the only identified target. No explicit firmware version range is documented, and the flaw is present in the current firmware at the time of the advisory.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity, while an EPSS score of 0.00155 (≈0.155%) suggests a very low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to deliver malicious input to the web interface of a logged‑in user, for example by sending the user a crafted link or injecting data through a form field, after which the script runs within the user’s browser context.
OpenCVE Enrichment