ZeroHour

CVE-2026-82777

niche

Authenticated OS Command Injection in Contec CONPROSYS PAC Series

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Contec's CONPROSYS PAC Series programmable automation controllers contain an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in input passed to operating-system commands. An attacker with valid login credentials to the device can submit crafted input, causing arbitrary OS commands to execute on the controller. Successful exploitation gives full control of the affected unit with high impact on confidentiality, integrity, and availability — significant in industrial control settings where these controllers monitor and operate physical processes. The flaw requires authentication (CVSS 4.0: 8.7, PR:L), so it is not exploitable by anonymous remote attackers, but compromised or default credentials would lower that barrier. No public proof-of-concept is known and the CVE is not in CISA's KEV catalog, with no evidence of in-the-wild exploitation to date.

What to do: Check the Contec/JPCERT/CC advisory for fixed firmware and upgrade affected CONPROSYS PAC units as patched versions become available. Until then, restrict management/login access to trusted networks via firewall rules or VPN, eliminate default and shared credentials, and grant device logins only to necessary accounts since exploitation requires authentication. Monitor device logs for unexpected command execution or configuration changes by low-privilege users.

Affected
Contec (CONTEC Co., Ltd.) CONPROSYS PAC Series
Estimated exposure
nichelikely hundreds to low thousands of internet-reachable units out of a larger installed base of industrial deployments (clearly an estimate) — CONPROSYS PAC Series controllers are niche industrial automation/IoT edge devices from a mid-sized Japanese vendor, and public internet scan data for comparable Contec industrial controllers typically shows only hundreds to low thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.