ZeroHour

CVE-2026-82780

niche

Authenticated Remote Code Execution via Dangerous File Upload in Contec CONPROSYS TM Series

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Contec's CONPROSYS TM Series industrial IoT gateways contain an unrestricted file upload vulnerability (CWE-434) that allows a remote authenticated attacker to upload a specially crafted file and execute arbitrary commands on the device. Exploitation requires valid login credentials for the product's interface, but once inside, the attacker gains full control of the gateway with high impact on its confidentiality, integrity, and availability. The flaw carries a CVSS 4.0 score of 8.7 (high) and was reported through Japanese CERT (JPCERT), consistent with Contec's footprint in Japanese industrial and building-monitoring deployments. Organizations running CONPROSYS TM Series devices for remote monitoring or control are affected. There is no known public proof of concept and no confirmed in-the-wild exploitation at this time.

What to do: Apply the firmware update specified in Contec's advisory for the affected CONPROSYS TM Series models as soon as it is available. In the interim, restrict management/upload access to trusted networks via VPN or firewall rules, review device logs for unexpected file uploads or unfamiliar account activity, and rotate credentials since exploitation requires valid authentication. Monitor the JPCERT/Contec advisories for the exact affected version list and update guidance.

Affected
Contec CONPROSYS TM Series
Estimated exposure
nichelikely hundreds to low thousands of deployed or internet-exposed devices — CONPROSYS TM Series units are niche Japanese industrial IoT gateways, and public internet scan services typically show only low hundreds of Contec gateway devices exposed, with total deployments plausibly in the low thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.

Weakness
CWE-434
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.