CVE-2026-82779
8.8Contec · CONPROSYS TM Series
A command injection vulnerability in the Contec CONPROSYS TM Series allows authenticated attackers to execute arbitrary OS commands.
Executive summary
An OS command injection vulnerability in the Contec CONPROSYS TM Series enables authenticated users to achieve arbitrary code execution, posing a high risk to system integrity.
Vulnerability
This flaw is a CWE-78 command injection vulnerability occurring within the CONPROSYS TM Series. An attacker with valid user credentials can leverage this flaw to execute unauthorized OS commands on the underlying device.
Business impact
The ability to execute arbitrary OS commands grants an attacker significant control over the affected industrial hardware. Successful exploitation could lead to full system compromise, unauthorized data modification, or the disruption of industrial control processes, resulting in operational downtime and potential safety risks. The CVSS score of 8.8 reflects the high severity of this impact, particularly for devices deployed in critical infrastructure environments.
Remediation
Immediate Action: Update the affected CONPROSYS TM Series devices to firmware version 2.19 or later as specified in the vendor security advisory.
Proactive Monitoring: Review device access logs for unusual command execution patterns or administrative actions performed by low-privileged user accounts.
Compensating Controls: Restrict network access to the device management interface to trusted administrative subnets only, ensuring that only authorized personnel can reach the login prompt.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for full system control and the high CVSS severity rating, administrators should prioritize the firmware update to version 2.19 across all affected CONPROSYS units. Organizations must ensure that access control policies are strictly enforced to minimize the risk of initial unauthorized authentication, which serves as the primary gateway for this attack vector.
More Contec CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section