CVE-2026-82789
niche1Authenticated Code Execution via Eval Injection in CONPROSYS HMI System
CONTEC's CONPROSYS HMI System (CHS), a web-based HMI used for industrial monitoring and control, contains an eval injection flaw (CWE-95) in which directives passed into dynamically evaluated code are not properly neutralized. An attacker who can log in to the product with valid (even low-privileged) credentials can submit crafted input that gets evaluated, resulting in arbitrary code execution on the HMI server. Successful exploitation could allow tampering with monitoring displays, manipulating collected process data, or pivoting deeper into the OT network, and carries a high CVSS v4.0 score of 8.7. Organizations running CHS in factory or building-automation environments are affected, though the advisory does not specify particular version ranges. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.
What to do: Apply the vendor's fixed version as identified in the CONTEC/JPCERT (JVN) advisory; until then, strictly limit who can log in to CHS with strong, unique credentials and role-based access, and keep the HMI interface off the internet inside a segmented OT network. Also review authentication and application logs for unexpected logins or unusual script/evaluation activity by legitimate accounts, since exploitation requires valid credentials.
| CONTEC CONPROSYS HMI System (CHS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
- Weakness
- CWE-95
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.