Executive brief
The Contec CONPROSYS IO-Link Master (CPSL-08P1EN) is an industrial device used to manage IO-Link communications in manufacturing and automation environments. A cross-site scripting vulnerability allows attackers to inject malicious scripts that execute in the web browsers of logged-in users, potentially leading to session hijacking, credential theft, or unauthorized control of the device's operations.
Technical details
This is a cross-site scripting (XSS) vulnerability (CWE-79) in the web interface of CPSL-08P1EN versions prior to 2.3.10. The vulnerability requires user interaction (a logged-in user must visit a malicious page), and the attack vector is network-based with no authentication required from the attacker's perspective. An attacker can craft a malicious URL or web page that, when visited by an authenticated user, executes arbitrary JavaScript in their browser context, potentially compromising the user's session, stealing credentials, or performing unauthorized actions on the device. The fix is available in version 2.3.10 and later.
Affected products
- Contec CONPROSYS IO-Link Master CPSL-08P1EN prior to 2.3.10
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory