Sceawere

Vulnerability Detail

CVE-2026-82792UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Contec CAN Converter XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.2
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
CAN-2-WF
Attack Type
Cross-site scripting (XSS)
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.2",
  "pubDate": "2026-09-14T07:17:21.343Z",
  "pubdate": "2026-09-14T07:17:21.343Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified in the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit.\nThe vulnerability allows an unauthenticated or authenticated attacker to inject and execute arbitrary malicious JavaScript within the context of a victim's web browser session.\nSuccessful exploitation compromises the integrity and confidentiality of the user's interaction with the device's web management interface.\nThe primary risk involves session hijacking, unauthorized configuration changes, or the redirection of the user to malicious external domains.\nThis vulnerability stems from improper neutralization of user-supplied input before rendering it in the browser, posing a significant risk to industrial communication infrastructure.\nExploitation requires the victim to access a specifically crafted URL or interact with a malicious page while maintaining an active session on the device.",
  "technicalDetails": "The vulnerability manifests as a Reflected Cross-Site Scripting (XSS) flaw within the web-based management interface of the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit.\nThe root cause is the insufficient sanitization of HTTP request parameters handled by the web server component, which fails to correctly encode or escape user-controlled input before reflecting it into the HTML document object model (DOM).\nAn attacker can exploit this by crafting a malicious URL containing a JavaScript payload within vulnerable input parameters. When a logged-in administrator or user clicks this link or is redirected to it, the injected script executes in the context of the device's web session.\nThe execution of arbitrary scripts occurs because the browser interprets the unsanitized input as legitimate executable code rather than plain text data.\nThe attack flow typically involves the following stages: 1) The attacker identifies a reflected parameter on the device's web management page. 2) The attacker crafts a payload utilizing common JavaScript injection vectors (e.g., <script> tags or event handlers like onload/onerror). 3) The attacker delivers the malicious URL to an authenticated user through phishing or social engineering. 4) The user's browser renders the page, executing the attacker's script under the domain of the converter's IP address.\nPost-exploitation, the attacker may perform unauthorized actions on behalf of the victim, such as modifying network settings, reading sensitive configuration data, or stealing authentication cookies to facilitate session hijacking. The impact is elevated given the operational criticality of CAN-to-LAN communication converters in industrial environments, where unauthorized access to the device can lead to broader network exposure or process disruption."
}
CVE-2026-82792: Contec CAN Converter XSS Vulnerability (MEDIUM Severity, CVSS: 5.2) | Sceawere