Impact
The vulnerability is an unvalidated cross‑site scripting flaw in the Schedule Settings and Mail Send Setting pages of SolarView Compact. An attacker scripts that are executed with the privileges of the logged‑in admin. The injected script can then invoke arbitrary operating‑system commands on the device, effectively allowing the attacker to take control of the system.
Affected Systems
Affected products are SolarView Compact monitors by Contec‑MC310 and SV‑ CVE description does not specify a firmware version range, so all released units with the firmware shipped to these devices should be considered vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS score of 5.1. Exploitation requires authenticated network‑level access; however, the EPSS score of < 1%, which is less than 1%, indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits are available yet. The capability to execute arbitrary OS commands results in a moderate level of risk for exposed systems.
OpenCVE Enrichment