Description
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary JavaScript execution in a logged‑in user’s browser via the Contec CAN‑2 converter web interface
Action: Assess & Mitigate
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw (CWE‑79) that allows an attacker to inject and execute arbitrary JavaScript when a logged‑in user accesses the Contec CAN‑2 web interface. The execution occurs in the context of the authenticated user’s browser and can manipulate the page, steal session data, or perform additional malicious actions.

Affected Systems

Products affected are Contec Co., Ltd. CAN‑2‑USB and CAN‑2‑WF converters, collectively known as the CAN 2.0B Communication Wireless LAN / USB Converter Unit. Version information was not provided, so all current releases are potentially affected.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate risk, and the EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated user to click a crafted link or load a malicious page through the web interface; host compromise is not expected by this flaw alone.

Generated by OpenCVE AI on September 15, 2026 at 14:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict or segment access to the CAN‑2 web interface to trusted administrators only
  • Deploy a strict Content Security Policy that disallows inline scripts and limits external JavaScript sources
  • Sanitize and validate all user‑supplied input before echoing it in server responses

Generated by OpenCVE AI on September 15, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec can-2-usb
Contec can-2-wf
Vendors & Products Contec
Contec can-2-usb
Contec can-2-wf

Tue, 15 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Arbitrary JavaScript Execution via XSS in Contec CAN‑2 Web Interface

Mon, 14 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Contec CAN‑2 Converter

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Contec CAN‑2 Converter

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Contec Can-2-usb Can-2-wf
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:57:52.643Z

Reserved: 2026-08-31T02:30:58.279Z

Link: CVE-2026-82792

cve-icon Vulnrichment

Updated: 2026-09-14T11:57:47.673Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:21.343

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:39Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')