Junglewise Threat Intelligence

CVE-2026-82790: Contec PC-HELPER Wireless I/O cross-site scripting

CVE-2026-82790 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec PC-HELPER Wireless I/O is a remote I/O control device commonly used in industrial and embedded systems. A cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts that execute in the context of a logged-in administrator's browser, potentially enabling unauthorized device configuration changes or data theft from the management interface.

Technical details

This vulnerability is a reflected cross-site scripting (XSS) flaw (CWE-79) in the web management interface of Contec PC-HELPER Wireless I/O devices. An attacker can craft a malicious URL or web page containing unsanitized input that, when visited by a logged-in user, executes arbitrary JavaScript in the user's browser with access to the management session. The vulnerability requires user interaction (clicking a link or visiting a page) and the victim must be authenticated to the device interface. Successful exploitation allows an attacker to perform arbitrary actions on the device, modify configurations, or steal sensitive data. The vendor has released firmware version 1.01.00 or later to remediate this issue.

Affected products

  • Contec PC-HELPER Wireless I/O DIO-0404RY-LWF prior to 1.01.00
  • Contec PC-HELPER Wireless I/O DIO-0404RY-LWF-US prior to 1.01.00

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References

Related threats