CVE-2026-82791
8.8Contec · CAN-2-WF, CAN-2-USB
An OS command injection vulnerability in Contec CAN-2-WF and CAN-2-USB devices allows authenticated attackers to execute arbitrary OS commands.
Executive summary
An OS command injection vulnerability in Contec communication converters allows authenticated attackers to gain full control over the device, posing a high risk of system compromise.
Vulnerability
The vulnerability is an OS command injection flaw (CWE-78) triggered through improper neutralization of special elements in the interface, requiring the attacker to have authenticated access to the device.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands at the operating system level, potentially leading to a complete loss of device integrity and unauthorized access to industrial communication networks. With a CVSS score of 8.8, this flaw represents a significant risk to operational stability and security, as compromised converters could be leveraged to bridge attacks into sensitive internal segments.
Remediation
Immediate Action: Update the firmware for all Contec CAN-2-WF and CAN-2-USB units to version 2.20 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor device logs for unusual administrative activity or unexpected system calls originating from the network management interface.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and employ network segmentation to isolate these converters from non-essential network traffic.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the severity of potential OS command injection, organizations using affected Contec hardware must prioritize firmware updates to version 2.20. Restricting management access is a necessary interim step to mitigate the risk until all devices can be patched.
More Contec CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section