Contec CO.,LTD. Vulnerabilities and Affected Products
Vulnerabilities associated with CONPROSYS HMI System (CHS).
Products
Clear product- CONPROSYS IoT Gateway products3 vulnerabilities
- CONPROSYS HMI System (CHS)2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-34081MEDIUM | CONPROSYS HMI System (CHS) < 3.7.7 Exposed PHP Debug InfoThe Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7.7. CWE-215Jul 1, 2025 | CVSS6.9v4.0 | EPSS0.599% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34080MEDIUM | CONPROSYS HMI System (CHS) < 3.7.7 Reflected Cross-Site ScriptingThe Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7. CWE-79Jul 1, 2025 | CVSS5.1v4.0 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |