Cross-site Scripting Vulnerability in CONPROSYS M2M Gateway and Controller Products
CVE-2026-82773

5.1MEDIUM

What is CVE-2026-82773?

A cross-site scripting vulnerability has been identified in the CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series by Contec. When exploited, this flaw allows an attacker to execute arbitrary scripts in the web browser of a logged-in user, posing a significant risk to user data and integrity. It is essential for users of these products to assess their systems for potential exploitation and take appropriate measures to mitigate this risk.

Affected Version(s)

M2M Controller Configurable type CPS-MCS341* 0 < 4.1.0

M2M Controller Integrated Type CPS-MC341 0 < 4.1.0

M2M Gateway Configurable type CPS-MGS341* 0 < 4.1.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.