ZeroHour

CVE-2026-82772

niche

Buffer Overflow Enables RCE in Contec EC1000 Series Web Service

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Contec EC1000 series embedded controllers contain a buffer overflow (CWE-120) in their built-in web service. A remote attacker who can reach the web interface and holds low-level privileges (such as a valid user account) can send a specially crafted request that overflows a buffer, resulting in execution of arbitrary programs on the device. Successful exploitation fully compromises the controller, with high impact on the confidentiality, integrity, and availability of the affected system and any equipment or processes it supervises. Organizations running EC1000 series units — typically industrial and IoT edge deployments, concentrated in the Japanese market where Contec operates — are the affected population. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and there is no evidence of exploitation in the wild.

What to do: Apply Contec's fixed firmware as soon as it is available under the vendor/JPCERT advisory, as no specific patched version is named in the current data. Until then, remove the EC1000 web service from internet exposure and restrict access to trusted management networks or VPNs with source allow-listing. Audit web-service logs for unusually long or malformed requests and rotate device credentials, since exploitation requires an attacker to already hold low-level privileges on the web interface.

Affected
Contec EC1000 series
Estimated exposure
nichelikely on the order of hundreds of internet-exposed devices (clearly an estimate) — Contec is a niche Japanese embedded/industrial vendor and EC1000 controllers are deployed in limited verticals and volumes, so the internet-facing population is expected to be small; no authoritative scan or install counts are available…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

Weakness
CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.