Junglewise Threat Intelligence

CVE-2026-82781: Contec CONPROSYS nano Series cross-site scripting

CVE-2026-82781 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Vendors: Contec.

Executive brief

CONPROSYS nano Series are industrial remote I/O coupler units used in manufacturing and automation environments. A cross-site scripting (XSS) vulnerability allows an attacker to inject arbitrary scripts that execute in the web browser of an authenticated user, potentially compromising operator sessions and enabling unauthorized control of industrial equipment or data theft.

Technical details

This is a stored or reflected cross-site scripting (CWE-79) vulnerability in the CONPROSYS nano Series web interface. The vulnerability requires user interaction (a logged-in user must view a crafted page) and authentication credentials, but operates over the network with low attack complexity. An attacker can inject malicious scripts that execute in the context of a logged-in user's session, allowing session hijacking, credential theft, or manipulation of industrial operations. Affected versions include CPSN-MCB271-* prior to 1.82, CPSN-EOB471EI-[]1 prior to 1.02, and CPSN-PCB271-S1-041 prior to 1.61. Patches are available in the specified patched versions.

Affected products

  • Contec CONPROSYS nano Series Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* prior to 1.82
  • Contec CONPROSYS nano Series Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 prior to 1.02
  • Contec CONPROSYS nano Series Programmable Remote I/O Coupler Unit CPSN-PCB271-S1-041 prior to 1.61

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References