CVE-2026-82773: Contec Co., Ltd m2m Controller Configurable Type Cps-MCS341*
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Affected products
- Contec Co., Ltd m2m Controller Configurable Type Cps-MCS341*: before 4.1.0 (fixed in 4.1.0)
- Contec Co., Ltd m2m Controller Integrated Type Cps-MC341: before 4.1.0 (fixed in 4.1.0)
- Contec Co., Ltd m2m Gateway Configurable Type Cps-MGS341*: before 4.1.0 (fixed in 4.1.0)
- Contec Co., Ltd m2m Gateway Integrated Type Cps-MG341*: before 4.1.0 (fixed in 4.1.0)
Published 2026-09-14. Last modified 2026-09-16.