Executive brief
Contec FLEXLAN industrial network devices contain a cross-site scripting (XSS) vulnerability in their web-based management interface. An attacker who can trick a logged-in administrator into visiting a malicious webpage could execute arbitrary scripts in the administrator's browser, potentially allowing them to modify device configurations, extract sensitive data, or perform unauthorized operations on the network devices.
Technical details
This is a stored or reflected cross-site scripting (CWE-79) vulnerability affecting Contec's FLEXLAN industrial control device series. The vulnerability exists in the web management interface and requires that an authenticated user be present (logged in). An attacker must craft a malicious payload and either inject it into the application or trick a logged-in user into visiting a malicious link. When executed, the injected script runs in the context of the victim's browser session, allowing potential session hijacking, configuration changes, or credential theft. Patches are available via firmware updates to versions 1.12.00 (FX5000), 1.14.00 (FX4000), and 1.20.00 (FX3000) or later.
Affected products
- Contec FX5000 series FXA5000, FXA5020, FXA5020-[][] versions prior to 1.12.00; FXE5000, FXE5000-[][], FXS5000-[][], FXS5021 versions prior to 1.12.00
- Contec FX4000 series FXE4000, FXE4000-WP versions prior to 1.14.00; FXS4000, FXS4020 versions prior to 1.14.00
- Contec FX3000 series FXA3000, FXA3000-[][], FXA3020, FXA3020-[][], FXA3200, FXE3000, FXE3000-[][], FXE3000-WP, FXS300[]-CN versions prior to 1.20.00
Timeline
- 2026-09-14: disclosed