ZeroHour

CVE-2026-82774

moderate

Authenticated OS Command Injection in CONTEC CONPROSYS M2M Gateway and Controller

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-82774 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in CONTEC's CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series, industrial IoT edge devices. A remote attacker with valid login credentials can submit crafted input containing special characters to a command parameter, causing the device to execute an arbitrary operating-system command. Successful exploitation gives the attacker full control of the appliance with high impact on its confidentiality, integrity, and availability (CVSS v4.0: 8.7), which typically means compromise of the industrial data collection, monitoring, and remote-management functions the gateway/controller performs. Only authenticated users can trigger the bug, so the practical risk combines with weak, default, or stolen credentials on internet-reachable management interfaces. There is no known public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation has been reported to date.

What to do: Apply CONTEC's patched firmware per the JPCERT/CONTEC advisory, since the advisory does not list fixed version numbers — check the vendor page for your specific model. Restrict management/web interfaces to trusted internal networks or VPNs rather than exposing them to the internet, and replace any default or shared credentials with strong unique ones since exploitation requires login. Review device logs for unexpected logins or command execution from unfamiliar sources or times.

Affected
CONTEC CONPROSYS M2M Gateway Seriesall (advisory names the entire series; no specific model or version range was provided)
CONTEC CONPROSYS M2M Controller Seriesall (advisory names the entire series; no specific model or version range was provided)
Estimated exposure
moderatelikely a few thousand to low tens of thousands of units deployed, with probably only hundreds internet-exposed — CONPROSYS is a specialized Japanese industrial IoT hardware line (sold mainly into Japanese factory/infrastructure monitoring), so deployment is far smaller than mainstream networking gear and the advisory provides no install or scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.