Impact
The vulnerability is a cross‑site scripting flaw that allows an attacker to inject arbitrary scripts into the web interface of the device when a user is logged in. An intruder could use this to steal session tokens, deface the interface, or tamper with configuration data viewed in the browser, compromising confidentiality and integrity of the device configuration.
Affected Systems
Contec Co., Ltd. PC‑HELPER Wireless I/O DIO‑0404RY-LWF and PC‑HELPER Wireless I/O DIO‑0404RY-LWF‑US are affected. The flaw applies to all current firmware releases of these models, as no versioning information was provided.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. The EPSS score of < 1% indicates a very low probability of exploitation, though it is not zero. The vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. The likely attack vector is the device’s web interface accessed by authenticated users; exploitation requires the user to be logged in, making the risk contingent on user access.
OpenCVE Enrichment