← Back to CVE List
CVE-2026-82773NVD
Vulnerability Summary
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
CVSS v4.0 Base Metrics — Score 5.1 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionActive
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.1 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Contec Co., Ltd. M2M Gateway Integrated Type CPS-MG341* < 4.1.0
- Contec Co., Ltd. M2M Gateway Configurable type CPS-MGS341* < 4.1.0
- Contec Co., Ltd. M2M Controller Integrated Type CPS-MC341 < 4.1.0
- Contec Co., Ltd. M2M Controller Configurable type CPS-MCS341* < 4.1.0
- Contec Co., Ltd. M2M Gateway Integrated Type CPS-MG341* 4.1.0
- Contec Co., Ltd. M2M Gateway Configurable type CPS-MGS341* 4.1.0
- Contec Co., Ltd. M2M Controller Integrated Type CPS-MC341 4.1.0
- Contec Co., Ltd. M2M Controller Configurable type CPS-MCS341* 4.1.0