CVE-2026-82772
nicheBuffer Overflow Enables RCE in Contec EC1000 Series Web Service
Contec EC1000 series embedded controllers contain a buffer overflow (CWE-120) in their built-in web service. A remote attacker who can reach the web interface and holds low-level privileges (such as a valid user account) can send a specially crafted request that overflows a buffer, resulting in execution of arbitrary programs on the device. Successful exploitation fully compromises the controller, with high impact on the confidentiality, integrity, and availability of the affected system and any equipment or processes it supervises. Organizations running EC1000 series units — typically industrial and IoT edge deployments, concentrated in the Japanese market where Contec operates — are the affected population. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and there is no evidence of exploitation in the wild.
What to do: Apply Contec's fixed firmware as soon as it is available under the vendor/JPCERT advisory, as no specific patched version is named in the current data. Until then, remove the EC1000 web service from internet exposure and restrict access to trusted management networks or VPNs with source allow-listing. Audit web-service logs for unusually long or malformed requests and rotate device credentials, since exploitation requires an attacker to already hold low-level privileges on the web interface.
| Contec EC1000 series | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
- Weakness
- CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.