CVE-2026-82774
moderateAuthenticated OS Command Injection in CONTEC CONPROSYS M2M Gateway and Controller
CVE-2026-82774 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in CONTEC's CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series, industrial IoT edge devices. A remote attacker with valid login credentials can submit crafted input containing special characters to a command parameter, causing the device to execute an arbitrary operating-system command. Successful exploitation gives the attacker full control of the appliance with high impact on its confidentiality, integrity, and availability (CVSS v4.0: 8.7), which typically means compromise of the industrial data collection, monitoring, and remote-management functions the gateway/controller performs. Only authenticated users can trigger the bug, so the practical risk combines with weak, default, or stolen credentials on internet-reachable management interfaces. There is no known public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation has been reported to date.
What to do: Apply CONTEC's patched firmware per the JPCERT/CONTEC advisory, since the advisory does not list fixed version numbers — check the vendor page for your specific model. Restrict management/web interfaces to trusted internal networks or VPNs rather than exposing them to the internet, and replace any default or shared credentials with strong unique ones since exploitation requires login. Review device logs for unexpected logins or command execution from unfamiliar sources or times.
| CONTEC CONPROSYS M2M Gateway Series | all (advisory names the entire series; no specific model or version range was provided) |
| CONTEC CONPROSYS M2M Controller Series | all (advisory names the entire series; no specific model or version range was provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.