Cross-Site Scripting Vulnerability in CONPROSYS nano Series by Contec
CVE-2026-82781

5.1MEDIUM

What is CVE-2026-82781?

A cross-site scripting vulnerability in Contec's CONPROSYS nano Series allows attackers to execute arbitrary scripts on a user's web browser when they are logged in. This could lead to unauthorized actions being performed in the context of the affected user.

Affected Version(s)

Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041 0 < 1.61

Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 0 < 1.02

Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* 0 < 1.82

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.