Executive brief
Contec CONPROSYS M2M Gateway and M2M Controller Series are industrial automation devices used for machine-to-machine communication and data collection in manufacturing and IoT environments. A cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts that execute in the browser of any logged-in user, potentially leading to unauthorized actions, data theft, or credential compromise within the industrial network.
Technical details
The vulnerability is a reflected or stored cross-site scripting (CWE-79) flaw in the CONPROSYS M2M Gateway Series (CPS-MG341* and CPS-MGS341* versions prior to 4.1.0) and M2M Controller Series (CPS-MC341 and CPS-MCS341* versions prior to 4.1.0). The attack requires user interaction—a logged-in user must view a malicious page or click a crafted link. An attacker can execute arbitrary JavaScript in the victim's browser context, potentially stealing session tokens, performing unauthorized operations, or redirecting to phishing sites. The vulnerability is remotely exploitable over the network without authentication to the device itself. Patches are available in version 4.1.0 and later.
Affected products
- Contec CONPROSYS M2M Gateway Series CPS-MG341* and CPS-MGS341* prior to 4.1.0
- Contec CONPROSYS M2M Controller Series CPS-MC341 and CPS-MCS341* prior to 4.1.0
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory