Sceawere

Vulnerability Detail

CVE-2026-82773UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CONPROSYS Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
M2M Gateway Integrated Type CPS-MG341*
Attack Type
Cross-site scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-14T07:17:18.690Z",
  "pubdate": "2026-09-14T07:17:18.690Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the web management interfaces of CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series.\nThe vulnerability allows an unauthenticated or authenticated attacker to inject malicious client-side scripts into the web application, which are subsequently rendered in the context of an unsuspecting logged-in user's browser session.\nSuccessful exploitation results in unauthorized script execution, potentially leading to session hijacking, credential theft, sensitive information disclosure, or unauthorized actions performed on behalf of the victim.\nThe risk is categorized as critical for operational technology environments where these devices manage industrial communication. The primary attack vector is the manipulation of web-based input fields that fail to properly sanitize or encode data before rendering it in the browser.\nThis flaw compromises the integrity and confidentiality of the administrative interface, posing a severe threat to the operational security of the connected M2M infrastructure.",
  "technicalDetails": "The vulnerability is characterized as an improperly sanitized input handling issue within the web-based management interface of the CONPROSYS M2M series.\nThe root cause originates from the application's failure to implement robust output encoding or strict input validation on user-supplied data transmitted to the gateway or controller.\nAttack flow typically follows these steps: 1) An attacker identifies input fields or parameters within the web interface that are reflected back to the user without proper validation (e.g., device naming, configuration settings, or monitoring labels). 2) The attacker submits a crafted payload containing malicious JavaScript (e.g., <script>alert(document.cookie)</script>) into these input vectors.\nUpon submission, the application stores the malicious string within the device's persistent memory or configuration database.\nWhen an authorized administrator or user navigates to the compromised page, the web interface serves the stored malicious payload to the browser.\nThe victim's browser, trusting the origin of the device's administrative web server, executes the script within the security context of the current session.\nThis execution allows the attacker to perform several post-exploitation actions, including stealing session cookies, capturing keystrokes, redirecting the user to malicious sites, or executing administrative functions via API calls within the web interface (CSRF-like behavior).\nGiven the nature of M2M gateway devices, this XSS vulnerability is particularly dangerous as it could be used to facilitate persistent access to the internal network by manipulating device settings or firmware configurations.\nThe vulnerability is prevalent in environments where the management interface is exposed to internal or external networks without additional access controls or web application firewalls to filter malicious syntax.\nThe lack of Content Security Policy (CSP) headers or similar browser-side security controls further exacerbates the vulnerability, as the browser will process any script included in the server's response."
}
CVE-2026-82773: CONPROSYS Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.1) | Sceawere