CVE-2025-34080: Contec Conprosys HMI System

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.

Affected products

  • Contec Conprosys HMI System: before 3.7.7 (fixed in 3.7.7)

Published 2025-07-01. Last modified 2026-06-17.