Executive brief
CONPROSYS nano Series are industrial remote I/O coupler units used in manufacturing and automation environments. A cross-site scripting (XSS) vulnerability allows an attacker to inject arbitrary scripts that execute in the web browser of an authenticated user, potentially compromising operator sessions and enabling unauthorized control of industrial equipment or data theft.
Technical details
This is a stored or reflected cross-site scripting (CWE-79) vulnerability in the CONPROSYS nano Series web interface. The vulnerability requires user interaction (a logged-in user must view a crafted page) and authentication credentials, but operates over the network with low attack complexity. An attacker can inject malicious scripts that execute in the context of a logged-in user's session, allowing session hijacking, credential theft, or manipulation of industrial operations. Affected versions include CPSN-MCB271-* prior to 1.82, CPSN-EOB471EI-[]1 prior to 1.02, and CPSN-PCB271-S1-041 prior to 1.61. Patches are available in the specified patched versions.
Affected products
- Contec CONPROSYS nano Series Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* prior to 1.82
- Contec CONPROSYS nano Series Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 prior to 1.02
- Contec CONPROSYS nano Series Programmable Remote I/O Coupler Unit CPSN-PCB271-S1-041 prior to 1.61
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory