Sceawere

Vulnerability Detail

CVE-2026-82776UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CONPROSYS PAC Series XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
Integrated Type CPS-PC341[][]-*-9201
Attack Type
Cross-site scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-14T07:17:19.113Z",
  "pubdate": "2026-09-14T07:17:19.113Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified within the CONPROSYS PAC Series, presenting a significant security risk to web-based management interfaces. This vulnerability allows unauthenticated or authenticated attackers to inject and execute arbitrary malicious scripts within the context of a legitimate user's browser session.\nThe vulnerability stems from improper validation or escaping of user-supplied input rendered by the web application. When exploited, the impact includes the potential for session hijacking, unauthorized actions performed on behalf of the administrator, credential theft, and the redirection of users to malicious external domains.\nGiven that CONPROSYS PAC Series devices are frequently deployed in industrial control environments, successful exploitation could facilitate lateral movement or serve as a vector for more complex attacks against the operational technology (OT) infrastructure. The risk is heightened as the vulnerability does not require complex infrastructure to exploit, merely a browser-based interaction. Organizations are advised to prioritize restricting administrative access to these interfaces and monitoring web traffic for anomalous patterns consistent with script injection attempts.",
  "technicalDetails": "The vulnerability is characterized as a Cross-Site Scripting (XSS) flaw, arising from the inadequate sanitization of input data before it is reflected back to the user's web browser. In the context of the CONPROSYS PAC Series, the web management interface fails to correctly neutralize special characters—such as <, >, \", and '—within specific parameters or fields that are rendered dynamically.\nThe attack flow typically initiates when an attacker crafts a malicious URI or injects a payload into a field that the application subsequently persists or reflects. Once a logged-in user accesses a page containing the injected content, the browser interprets the malicious script as legitimate application code due to the absence of proper context-aware encoding. This execution occurs within the security boundary of the web session, granting the script access to the Document Object Model (DOM), browser cookies, and session tokens.\nTechnically, the vulnerability functions as a Reflected or Stored XSS depending on whether the payload is immediately returned to the victim or stored within the device's configuration or log files for future execution. If the latter is true, the vulnerability manifests as a persistent threat that executes every time the affected page is loaded by an authorized user, regardless of whether the attacker is currently present.\nExploitation requires the victim to have an active, authenticated session with the CONPROSYS PAC Series web interface. Upon execution of the payload, the script can perform various post-exploitation actions, including: 1) Performing administrative tasks (e.g., changing device configuration or modifying user accounts) by making background HTTP requests (XHR/Fetch) that inherit the user's credentials; 2) Stealing session cookies, specifically those lacking the 'HttpOnly' flag, to facilitate session hijacking; 3) Defacing the administrative dashboard; and 4) Redirecting the victim to a malicious phishing site designed to harvest administrative credentials.\nThe scope of this vulnerability extends to the web server component of the CONPROSYS PAC Series hardware. Because these devices often operate in network segments that bridge OT and IT environments, the potential for an XSS-based compromise to act as a foothold for further network exploitation is considerable. The absence of robust Content Security Policy (CSP) headers in the web application's response further exacerbates the risk, allowing virtually unrestricted execution of unauthorized client-side scripts."
}
CVE-2026-82776: CONPROSYS PAC Series XSS Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere