Impact
The vulnerability is a cross‑site scripting flaw (CWE‑79) that allows an attacker to inject and execute arbitrary JavaScript when a logged‑in user accesses the Contec CAN‑2 web interface. The execution occurs in the context of the authenticated user’s browser and can manipulate the page, steal session data, or perform additional malicious actions.
Affected Systems
Products affected are Contec Co., Ltd. CAN‑2‑USB and CAN‑2‑WF converters, collectively known as the CAN 2.0B Communication Wireless LAN / USB Converter Unit. Version information was not provided, so all current releases are potentially affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate risk, and the EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated user to click a crafted link or load a malicious page through the web interface; host compromise is not expected by this flaw alone.
OpenCVE Enrichment