ZeroHour

CVE-2026-82762

niche

Authenticated OS Command Injection in Contec FX3000/FX4000/FX5000 Series

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

An OS command injection vulnerability (CWE-78) exists in Contec's FX5000, FX4000, and FX3000 series devices, caused by improper neutralization of special elements in input that is passed to operating-system commands. The flaw is exploitable over the network by an attacker who can log in to the product with valid, low-privilege credentials, giving it a CVSS 4.0 score of 8.7 (high). Successful exploitation allows arbitrary OS command execution on the affected device, compromising its confidentiality, integrity, and availability. Organizations running these Contec FX-series units — typically industrial/factory-automation or control environments — are affected, with the strongest risk on devices whose login interfaces are reachable by untrusted users or networks. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and there is no evidence of exploitation in the wild.

What to do: Update affected FX3000, FX4000, and FX5000 devices to the fixed firmware versions listed in Contec's official advisory (issued via JPCERT/Contec support) as soon as they are available. Until patched, restrict login and management access to trusted administrative networks and users only, enforce strong unique credentials, and disable or prune unused accounts since the flaw requires valid login. Monitor device logs and network traffic for unexpected commands or configuration changes originating from device user sessions.

Affected
Contec FX5000 seriesAll FX5000 series devices (specific firmware versions not enumerated in the CVE data)
Contec FX4000 seriesAll FX4000 series devices (specific firmware versions not enumerated in the CVE data)
Contec FX3000 seriesAll FX3000 series devices (specific firmware versions not enumerated in the CVE data)
Estimated exposure
nicheLikely hundreds to low thousands of devices worldwide; exact count unknown — Contec is a niche Japanese industrial-automation vendor whose FX-series devices are typically deployed in limited numbers on internal factory/OT networks, and no public active-install or internet-scan counts are available for these series,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.