Vulnerability record · CVE-2021-20660 · published 24 February 2021
CVE-2021-20660: SolarView Compact firmware cross-site scripting
Contec · Sv Cpt Mc310 Firmware
SolarView Compact SV-CPT-MC310 firmware before Ver.6.5 contains a reflected cross-site scripting flaw (CWE-79) reachable through unspecified vectors. An attacker can inject arbitrary script that executes in a victim's browser in the context of the affected device interface. The record does not name the vulnerable parameter or page, so the exact injection point is unknown.
Description
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 medium severity with no confirmed exploitation or KEV listing, but a high EPSS percentile and network-reachable XSS warrant timely patching.
What it is
SolarView Compact SV-CPT-MC310 firmware before Ver.6.5 contains a reflected cross-site scripting flaw (CWE-79) reachable through unspecified vectors. An attacker can inject arbitrary script that executes in a victim's browser in the context of the affected device interface. The record does not name the vulnerable parameter or page, so the exact injection point is unknown.
Impact
An attacker can run arbitrary script in a victim's browser session against the SolarView Compact device, potentially stealing session data or performing actions as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires the victim to trigger the crafted request (UI:R), consistent with a reflected XSS delivered via a link or page. No authentication is needed to deliver the payload, though the victim must interact.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation activity is documented in the references, which are only vendor and third-party advisories. EPSS is high (0.47165, ~98.8th percentile), suggesting elevated likelihood of attempted exploitation, but this is a probability estimate, not confirmed exploitation.
What to do
- Upgrade SolarView Compact SV-CPT-MC310 firmware to Ver.6.5 or later per the Contec vendor advisory.
- If immediate upgrade is not possible, restrict network access to the device interface to trusted management networks only.
- Deploy a WAF or input-filtering rule to block script injection attempts against the device web interface.
- Advise users not to follow untrusted links or open untrusted pages while authenticated to the device.
- Monitor vendor advisories for updated guidance on the unspecified injection vectors.
Detection
- Inspect web server and proxy logs for requests to the SolarView Compact interface containing script tags or encoded script payloads in parameters.
- Alert on unexpected outbound or referrer traffic from the device interface that could indicate script exfiltration.
- Review browser or endpoint telemetry for script execution originating from the device's web UI.
- Correlate access to the device interface with known scanning or probing activity against SolarView Compact endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-20660 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20660), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.