Sceawere

Vulnerability Detail

CVE-2026-82788UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CPSL-08P1EN Cross-Site Scripting Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
CPSL-08P1EN
Attack Type
Cross-site scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-14T07:17:20.790Z",
  "pubdate": "2026-09-14T07:17:20.790Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified in the CPSL-08P1EN product, allowing for the injection and execution of arbitrary client-side scripts within the context of a victim's web browser session.\nThe vulnerability occurs due to improper sanitization or validation of user-supplied input before it is reflected back to the user within the web application interface.\nSuccessful exploitation permits an attacker to execute malicious JavaScript in the victim's browser, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive information.\nThis vulnerability impacts the CPSL-08P1EN device, posing a significant risk to the integrity and confidentiality of user interactions within the web-based management interface.\nAttackers can leverage this flaw by inducing an authenticated user to visit a specially crafted malicious link or by manipulating input fields that are subsequently processed and rendered by the application.\nThe exploit requires the victim to be currently logged into the web interface, limiting the attack surface to active sessions but providing high impact due to the potential for unauthorized administrative or user operations.",
  "technicalDetails": "The vulnerability is categorized as a Cross-Site Scripting (XSS) flaw within the CPSL-08P1EN web-based administrative or user interface. It originates from a failure in the application's input handling mechanisms, specifically where user-controlled input is accepted, processed, and subsequently reflected in the HTTP response without adequate encoding or sanitization.\nIn a standard XSS attack flow, the vulnerability is exploited by injecting malicious script payloads into application input vectors. These vectors may include URL parameters, form fields, or header information that the server-side application logic fails to treat as untrusted data. When the application renders this data in the Document Object Model (DOM) of the browser, the browser interprets the injected payload as executable code rather than plain text.\nThe exploitation process typically follows a predictable sequence: First, the attacker identifies an input field or parameter that reflects input onto the page. Second, the attacker crafts a malicious payload containing JavaScript, such as 'script' tags or event handlers (e.g., 'onload', 'onerror'), designed to execute in the context of the user's browser session. Third, the attacker delivers this payload to the victim, often through social engineering via a crafted URL or by injecting the code into a persistent field (stored XSS).\nOnce the victim views the affected page while logged into the CPSL-08P1EN interface, the malicious script executes within the security context of the application's origin. This enables the attacker to bypass the Same-Origin Policy (SOP), granting access to the victim's session cookies, local storage, or session tokens. Furthermore, the script can perform unauthorized actions on behalf of the user, such as modifying device configurations, triggering firmware updates, or exfiltrating sensitive operational data.\nThe scope of impact depends on the privileges of the victim; if an administrator is targeted, the attacker may gain full control over the CPSL-08P1EN unit. The vulnerability is characterized by a lack of context-aware output encoding (e.g., HTML entity encoding) at the application layer, which is required to prevent the browser from misinterpreting user data as active content. The absence of modern security headers like Content-Security-Policy (CSP) further facilitates the execution of external or unauthorized scripts, exacerbating the potential impact of this cross-site scripting vector."
}
CVE-2026-82788: CPSL-08P1EN Cross-Site Scripting Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere