Executive brief
Contec industrial IoT and automation products contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick logged-in users into performing unintended operations. An authenticated user viewing a malicious webpage could unknowingly trigger administrative actions, system modifications, or configuration changes without their knowledge, potentially compromising operational integrity.
Technical details
A cross-site request forgery (CWE-352) vulnerability exists in multiple Contec products including the PC-HELPER series and CONPROSYS series. The vulnerability allows an attacker to craft a malicious webpage that, when viewed by a user already logged into an affected Contec product, will cause the victim's browser to send authenticated requests on the attacker's behalf. The attack requires user interaction (visiting a malicious page while authenticated) but no special privileges. An attacker can perform any action that the logged-in user is authorized to perform, potentially including system configuration changes, data manipulation, or network topology modifications.
Affected products
- Contec PC-HELPER Wireless I/O DIO-0404RY-LWF prior to 1.01.00
- Contec PC-HELPER Wireless I/O DIO-0404RY-LWF-US prior to 1.01.00
- Contec CONPROSYS nano Remote I/O Coupler Unit CPSN-MCB271 prior to 1.82
- Contec CONPROSYS nano Remote I/O Coupler Unit CPSN-EOB471EI prior to 1.02
- Contec CONPROSYS nano Programmable Remote I/O Coupler Unit CPSN-PCB271-S1-041 prior to 1.61
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory