CVE-2026-82762
nicheAuthenticated OS Command Injection in Contec FX3000/FX4000/FX5000 Series
An OS command injection vulnerability (CWE-78) exists in Contec's FX5000, FX4000, and FX3000 series devices, caused by improper neutralization of special elements in input that is passed to operating-system commands. The flaw is exploitable over the network by an attacker who can log in to the product with valid, low-privilege credentials, giving it a CVSS 4.0 score of 8.7 (high). Successful exploitation allows arbitrary OS command execution on the affected device, compromising its confidentiality, integrity, and availability. Organizations running these Contec FX-series units — typically industrial/factory-automation or control environments — are affected, with the strongest risk on devices whose login interfaces are reachable by untrusted users or networks. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and there is no evidence of exploitation in the wild.
What to do: Update affected FX3000, FX4000, and FX5000 devices to the fixed firmware versions listed in Contec's official advisory (issued via JPCERT/Contec support) as soon as they are available. Until patched, restrict login and management access to trusted administrative networks and users only, enforce strong unique credentials, and disable or prune unused accounts since the flaw requires valid login. Monitor device logs and network traffic for unexpected commands or configuration changes originating from device user sessions.
| Contec FX5000 series | All FX5000 series devices (specific firmware versions not enumerated in the CVE data) |
| Contec FX4000 series | All FX4000 series devices (specific firmware versions not enumerated in the CVE data) |
| Contec FX3000 series | All FX3000 series devices (specific firmware versions not enumerated in the CVE data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.