CVE-2026-82777
8.8Contec · CONPROSYS PAC Series
A command injection vulnerability in the Contec CONPROSYS PAC Series allows an authenticated attacker to execute arbitrary OS commands on the device.
Executive summary
An OS command injection vulnerability in the Contec CONPROSYS PAC Series allows authenticated attackers to execute arbitrary system commands, posing a severe risk to device integrity.
Vulnerability
This vulnerability (CWE-78) involves improper neutralization of special elements in OS commands. An attacker with valid credentials can interact with the system to execute arbitrary commands, potentially leading to full control over the affected industrial controller.
Business impact
Successful exploitation allows an attacker to gain unauthorized control over the industrial controller, which may lead to the compromise of operational technology environments. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk that could result in significant production downtime, unauthorized system modifications, or the disruption of critical industrial processes.
Remediation
Immediate Action: Update the firmware for the affected CONPROSYS PAC Series devices to version 3.0.0 or later as provided in the official Contec security advisory.
Proactive Monitoring: Monitor system logs for unusual command execution patterns or unauthorized attempts to access administrative functions within the device interface.
Compensating Controls: Restrict network access to the management interfaces of these devices to trusted internal subnets only, and implement strict credential management policies to minimize the risk of unauthorized authenticated access.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high severity of this command injection flaw, organizations utilizing the Contec CONPROSYS PAC Series must prioritize the update to version 3.0.0. Ensure that all affected units are identified and patched immediately to prevent potential unauthorized system-level command execution.
More Contec CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section