CVE-2026-82773

Summary

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Affected Software

VendorProductVersion RangeStatus
Contec Co., Ltd.M2M Gateway Integrated Type CPS-MG341*0 < 4.1.0affected
Contec Co., Ltd.M2M Gateway Configurable type CPS-MGS341*0 < 4.1.0affected
Contec Co., Ltd.M2M Controller Integrated Type CPS-MC3410 < 4.1.0affected
Contec Co., Ltd.M2M Controller Configurable type CPS-MCS341*0 < 4.1.0affected

Weaknesses

  • CWE-79: Cross-site scripting (XSS)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References