ZeroHour

CVE-2026-82779

moderate

Authenticated OS Command Injection in Contec CONPROSYS TM Series Industrial Controllers

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

An OS command injection flaw (CWE-78) exists in Contec's CONPROSYS TM Series of industrial edge computers/M2M-IoT controllers: the product fails to neutralize special elements before incorporating input into an OS command. An attacker who can log in to the device — any authenticated account, including a low-privileged one — can inject arbitrary shell commands that execute on the controller, effectively giving full control of the unit (high impact to confidentiality, integrity, and availability; CVSS v4.0 8.7). The flaw affects CONPROSYS TM Series deployments, which are typically used for industrial monitoring, control, and remote data collection in factories and infrastructure. Because exploitation requires valid credentials plus network access to the device's interface, internet-exposed consoles and shared or weak device accounts are the principal risk. There is no known in-the-wild exploitation, no public proof of concept, and the CVE is not on the CISA KEV catalog.

What to do: Apply the fixed firmware/software Contec issued for the CONPROSYS TM Series (check the Contec/JPCERT advisory for the exact fixed versions), noting that exploitation needs only a low-privileged login. Until patched, remove device management/web interfaces from the internet, restrict access to trusted VPN or admin subnets, and audit and rotate all device account credentials. Review device logs for unexpected command execution, processes, or configuration changes and escalate anomalies to your SOC.

Affected
Contec CONPROSYS TM Series (industrial edge computers / M2M-IoT controllers)
Estimated exposure
moderateplausibly tens of thousands of units deployed worldwide, of which likely only hundreds to a few thousand are internet-exposed (clearly an estimate) — CONPROSYS TM Series is a niche line of industrial edge controllers from mid-size Japanese vendor Contec; public scan engines typically show only hundreds to low thousands of exposed units for such OT product lines, with most deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.