CVE-2026-82794
8.8Contec · SolarView Compact
Contec SolarView Compact devices are vulnerable to OS command injection within the Schedule Settings, allowing authenticated attackers to execute arbitrary system commands.
Executive summary
The Contec SolarView Compact energy management system is affected by an OS command injection vulnerability that allows authenticated attackers to gain full control over the underlying operating system.
Vulnerability
This is an OS command injection vulnerability (CWE-78) located in the Schedule Settings functionality. It allows an attacker with low-level administrative or user credentials to inject and execute arbitrary OS commands on the appliance.
Business impact
Successful exploitation of this flaw grants an attacker the ability to execute arbitrary commands with the privileges of the application, leading to complete system compromise. Given the CVSS score of 8.8, this vulnerability poses a high risk to operational continuity, potentially allowing for unauthorized data exfiltration, lateral movement within the network, or permanent denial of service.
Remediation
Immediate Action: Update all affected SV-CPT-MC310 and SV-CPT-MC310F devices to firmware version 9.00 or later as provided by the Contec security advisory.
Proactive Monitoring: Inspect system logs for suspicious activity within the Schedule Settings module and monitor for unexpected outbound network connections originating from the device.
Compensating Controls: Restrict management interface access to trusted internal IP addresses only, and implement strict network segmentation to limit the potential blast radius if the device is compromised.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The vulnerability represents a critical security gap in Contec power management infrastructure. Security teams should prioritize the deployment of firmware version 9.00 to all production units. Due to the nature of command injection, failing to patch this device could provide a persistent foothold for attackers within your industrial control or management network.
More Contec CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section