PSI GridConnect Telecontrol
PSI GridConnect telecontrol devices contain a cross-site scripting (XSS) vulnerability in the web interface that allows authenticated attackers to inject and execute dynamic scripts. Successful exploitation could allow an attacker to perform actions in the context of logged-in operators or view sensitive configuration data. The vulnerability affects Smart Telecontrol Unit TCG, IEC104 Security Proxy, and Telecontrol Gateway models (VM, 3G, XS-MU). Older product versions (4.2.x and 5.0.x) are no longer supported and will not receive patches.
- Network access to the device's web interface (TCP port 80 or 443)
- Valid login credentials for the web interface
Patching may require device reboot — plan for process interruption
/api/v1/advisories/142cfe4f-44ae-4668-abb9-f5a8ffd666e8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.