Executive brief
Contec EC1000 series are industrial networking devices used to manage and control network infrastructure. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that execute in the web browser of authenticated users. This could lead to session hijacking, credential theft, or unauthorized configuration changes to critical network equipment.
Technical details
A cross-site scripting vulnerability (CWE-79) exists in the Contec EC1000 series web interface. The vulnerability requires an authenticated user to be logged in and user interaction (viewing a malicious page). An attacker can inject arbitrary scripts that execute in the victim's browser context, potentially allowing session theft, credential harvesting, or unauthorized administrative actions. The vulnerability affects ECE1000, ECE1020, and ECS1020 devices running firmware versions prior to 1.02. Firmware updates are available from Contec to remediate this issue.
Affected products
- Contec EC1000 series ECE1000, ECE1020, ECS1020 versions prior to 1.02
Timeline
- 2026-09-14: disclosed: Vulnerability disclosed via NVD and JVN