CVE-2026-82779
moderateAuthenticated OS Command Injection in Contec CONPROSYS TM Series Industrial Controllers
An OS command injection flaw (CWE-78) exists in Contec's CONPROSYS TM Series of industrial edge computers/M2M-IoT controllers: the product fails to neutralize special elements before incorporating input into an OS command. An attacker who can log in to the device — any authenticated account, including a low-privileged one — can inject arbitrary shell commands that execute on the controller, effectively giving full control of the unit (high impact to confidentiality, integrity, and availability; CVSS v4.0 8.7). The flaw affects CONPROSYS TM Series deployments, which are typically used for industrial monitoring, control, and remote data collection in factories and infrastructure. Because exploitation requires valid credentials plus network access to the device's interface, internet-exposed consoles and shared or weak device accounts are the principal risk. There is no known in-the-wild exploitation, no public proof of concept, and the CVE is not on the CISA KEV catalog.
What to do: Apply the fixed firmware/software Contec issued for the CONPROSYS TM Series (check the Contec/JPCERT advisory for the exact fixed versions), noting that exploitation needs only a low-privileged login. Until patched, remove device management/web interfaces from the internet, restrict access to trusted VPN or admin subnets, and audit and rotate all device account credentials. Review device logs for unexpected command execution, processes, or configuration changes and escalate anomalies to your SOC.
| Contec CONPROSYS TM Series (industrial edge computers / M2M-IoT controllers) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.