CVE-2026-82793

7.2

Contec · CAN-2-WF and CAN-2-USB

An unrestricted file upload vulnerability in Contec CAN-2-WF and CAN-2-USB converters allows remote authenticated attackers to execute arbitrary code.

Executive summary

A high-severity file upload vulnerability in Contec communication hardware allows remote authenticated attackers to achieve arbitrary code execution, posing a significant risk to device integrity.

Vulnerability

The device suffers from an unrestricted file upload flaw (CWE-434), which permits a remote attacker with authenticated access to upload malicious files that trigger arbitrary code execution on the underlying hardware.

Business impact

Successful exploitation allows an attacker to gain control over the communication converter unit, potentially leading to unauthorized data interception, system disruption, or lateral movement within the industrial network. With a CVSS score of 7.2, this vulnerability represents a high risk to operational continuity and the security of the connected infrastructure.

Remediation

Immediate Action: Update all affected Contec CAN-2-WF and CAN-2-USB units to firmware version 2.20 or later as provided in the vendor security advisory.

Proactive Monitoring: Review device access logs for unusual file upload activity or entries from unauthorized administrative accounts.

Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only and ensure the device is isolated from untrusted networks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of the impact and the potential for full system compromise, administrators should prioritize updating the firmware for all identified Contec units. Ensure that access controls are strictly enforced to prevent unauthorized users from leveraging the management interface.

More Contec CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources