CVE-2026-82770
8.8Contec · RP-WAH-SR Series
A buffer overflow vulnerability in the Contec RP-WAH-SR series web service allows a remote authenticated attacker to execute arbitrary code via a specially crafted request.
Executive summary
A critical buffer overflow vulnerability in Contec RP-WAH-SR devices allows remote code execution, posing a severe risk to network infrastructure integrity.
Vulnerability
The device is susceptible to a buffer overflow (CWE-120) within its web service component. An authenticated attacker can trigger this flaw by sending a malicious request, resulting in the execution of arbitrary code on the affected hardware.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution, granting them full control over the affected network device. This level of compromise can lead to complete loss of confidentiality, integrity, and availability of the device, potentially facilitating lateral movement into the internal network. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that requires immediate remediation to prevent unauthorized system access.
Remediation
Immediate Action: Update the firmware on all affected Contec RP-WAH-SR devices to the specified fixed versions: 1.03 for SR1 and SR2 models, or 1.02 for SR12 and SR22 models.
Proactive Monitoring: Monitor device access logs for unusual traffic patterns or malformed HTTP requests directed at the web management interface.
Compensating Controls: Restrict access to the web management interface of these devices to trusted management IP addresses only, and utilize a firewall to drop suspicious requests.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the potential for remote code execution, necessitates prompt action. Administrators should verify their device firmware versions against the vendor advisory and apply the necessary patches immediately to secure their infrastructure against potential compromise.
More Contec CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section