CVE-2026-82793
7.2Contec · CAN-2-WF and CAN-2-USB
An unrestricted file upload vulnerability in Contec CAN-2-WF and CAN-2-USB converters allows remote authenticated attackers to execute arbitrary code.
Executive summary
A high-severity file upload vulnerability in Contec communication hardware allows remote authenticated attackers to achieve arbitrary code execution, posing a significant risk to device integrity.
Vulnerability
The device suffers from an unrestricted file upload flaw (CWE-434), which permits a remote attacker with authenticated access to upload malicious files that trigger arbitrary code execution on the underlying hardware.
Business impact
Successful exploitation allows an attacker to gain control over the communication converter unit, potentially leading to unauthorized data interception, system disruption, or lateral movement within the industrial network. With a CVSS score of 7.2, this vulnerability represents a high risk to operational continuity and the security of the connected infrastructure.
Remediation
Immediate Action: Update all affected Contec CAN-2-WF and CAN-2-USB units to firmware version 2.20 or later as provided in the vendor security advisory.
Proactive Monitoring: Review device access logs for unusual file upload activity or entries from unauthorized administrative accounts.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only and ensure the device is isolated from untrusted networks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of the impact and the potential for full system compromise, administrators should prioritize updating the firmware for all identified Contec units. Ensure that access controls are strictly enforced to prevent unauthorized users from leveraging the management interface.
More Contec CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section