Junglewise Threat Intelligence

CVE-2026-82792: Contec CAN 2.0B Communication Unit cross-site scripting

CVE-2026-82792 · Severity: medium · CVSS 5.2 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec CAN 2.0B Communication Wireless LAN / USB Converter Units contain a cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the browsers of logged-in users. An attacker can craft a malicious webpage that, when visited by an authenticated user, injects and executes scripts with access to the user's session, potentially compromising device settings or customer data.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw affecting Contec CAN 2.0B Communication devices (CAN-2-WF and CAN-2-USB units) running firmware versions prior to 2.20. It requires network access and user interaction: an authenticated user must view a specially crafted webpage while logged into the device's web interface. The attack vector is network-based and requires the victim to be logged in to the affected product. An attacker can execute arbitrary JavaScript in the victim's browser context, potentially leading to unauthorized configuration changes or data theft. The vulnerability is resolved in firmware version 2.20 and later.

Affected products

  • Contec CAN-2-WF prior to 2.20
  • Contec CAN-2-USB prior to 2.20

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References

Related threats