Executive brief
Contec RP-WAH-SR Series is a network appliance used for industrial remote access. A cross-site scripting (XSS) vulnerability in the web interface could allow an attacker to execute arbitrary JavaScript in the browser of a logged-in administrator, potentially leading to unauthorized configuration changes, credential theft, or further compromise of the device.
Technical details
A stored or reflected cross-site scripting vulnerability (CWE-79) exists in the Contec RP-WAH-SR Series web interface. The vulnerability allows injection of arbitrary script that will execute in the context of a logged-in user's browser session. Exploitation requires user interaction (a logged-in user viewing a specially crafted page) and does not require elevated privileges. An attacker could bypass the security perimeter of the device and compromise administrative sessions, potentially gaining control of the device's configuration and network access rules. Patches are available; users should update the firmware to version 1.03 for RP-WAH-SR1 and RP-WAH-SR2, or version 1.02 for RP-WAH-SR12 and RP-WAH-SR22.
Affected products
- Contec RP-WAH-SR1 prior to 1.03
- Contec RP-WAH-SR2 prior to 1.03
- Contec RP-WAH-SR12 prior to 1.02
- Contec RP-WAH-SR22 prior to 1.02
Timeline
- 2026-09-14: disclosed