CVE-2026-82780
nicheAuthenticated Remote Code Execution via Dangerous File Upload in Contec CONPROSYS TM Series
Contec's CONPROSYS TM Series industrial IoT gateways contain an unrestricted file upload vulnerability (CWE-434) that allows a remote authenticated attacker to upload a specially crafted file and execute arbitrary commands on the device. Exploitation requires valid login credentials for the product's interface, but once inside, the attacker gains full control of the gateway with high impact on its confidentiality, integrity, and availability. The flaw carries a CVSS 4.0 score of 8.7 (high) and was reported through Japanese CERT (JPCERT), consistent with Contec's footprint in Japanese industrial and building-monitoring deployments. Organizations running CONPROSYS TM Series devices for remote monitoring or control are affected. There is no known public proof of concept and no confirmed in-the-wild exploitation at this time.
What to do: Apply the firmware update specified in Contec's advisory for the affected CONPROSYS TM Series models as soon as it is available. In the interim, restrict management/upload access to trusted networks via VPN or firewall rules, review device logs for unexpected file uploads or unfamiliar account activity, and rotate credentials since exploitation requires valid authentication. Monitor the JPCERT/Contec advisories for the exact affected version list and update guidance.
| Contec CONPROSYS TM Series | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.