Impact
SolarView Compact contains a cross‑site scripting flaw in its image‑management interface. By injecting malicious script data, an authenticated attacker may trigger arbitrary OS command execution, compromising the device’s integrity. This is a typical input‑validation weakness mapped to CWE‑79.
Affected Systems
The flaw affects Contec Co., Ltd. devices SV‑CPT‑MC310 and SV‑CPT‑MC310F. No specific firmware revisions are listed, so current or future releases of these models may be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 5.1 places the issue in the medium‑range severity category. The EPSS score is < 1 % and it is not listed in CISA KEV, indicating no confirmed widespread exploitation at this time. The attack requires authenticated access to the device; based on the description, the likely attack vector is through the image upload or metadata fields in the image‑management module, which, if exploited, allows the attacker to invoke arbitrary OS commands.
OpenCVE Enrichment