ZeroHour

CVE-2026-82789

niche1

Authenticated Code Execution via Eval Injection in CONPROSYS HMI System

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CONTEC's CONPROSYS HMI System (CHS), a web-based HMI used for industrial monitoring and control, contains an eval injection flaw (CWE-95) in which directives passed into dynamically evaluated code are not properly neutralized. An attacker who can log in to the product with valid (even low-privileged) credentials can submit crafted input that gets evaluated, resulting in arbitrary code execution on the HMI server. Successful exploitation could allow tampering with monitoring displays, manipulating collected process data, or pivoting deeper into the OT network, and carries a high CVSS v4.0 score of 8.7. Organizations running CHS in factory or building-automation environments are affected, though the advisory does not specify particular version ranges. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.

What to do: Apply the vendor's fixed version as identified in the CONTEC/JPCERT (JVN) advisory; until then, strictly limit who can log in to CHS with strong, unique credentials and role-based access, and keep the HMI interface off the internet inside a segmented OT network. Also review authentication and application logs for unexpected logins or unusual script/evaluation activity by legitimate accounts, since exploitation requires valid credentials.

Affected
CONTEC CONPROSYS HMI System (CHS)
Estimated exposure
nichelikely hundreds to low thousands of installations worldwide (order of magnitude 10²–10³), an estimate only — CONPROSYS HMI System is a specialized Japanese industrial HMI product deployed in limited numbers at factory and building-automation sites, and HMIs of this class are typically kept off the public internet; no active-install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

Weakness
CWE-95
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.