CVE-2026-82777
nicheAuthenticated OS Command Injection in Contec CONPROSYS PAC Series
Contec's CONPROSYS PAC Series programmable automation controllers contain an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in input passed to operating-system commands. An attacker with valid login credentials to the device can submit crafted input, causing arbitrary OS commands to execute on the controller. Successful exploitation gives full control of the affected unit with high impact on confidentiality, integrity, and availability — significant in industrial control settings where these controllers monitor and operate physical processes. The flaw requires authentication (CVSS 4.0: 8.7, PR:L), so it is not exploitable by anonymous remote attackers, but compromised or default credentials would lower that barrier. No public proof-of-concept is known and the CVE is not in CISA's KEV catalog, with no evidence of in-the-wild exploitation to date.
What to do: Check the Contec/JPCERT/CC advisory for fixed firmware and upgrade affected CONPROSYS PAC units as patched versions become available. Until then, restrict management/login access to trusted networks via firewall rules or VPN, eliminate default and shared credentials, and grant device logins only to necessary accounts since exploitation requires authentication. Monitor device logs for unexpected command execution or configuration changes by low-privilege users.
| Contec (CONTEC Co., Ltd.) CONPROSYS PAC Series | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.