ZeroHour

CVE-2026-82791

niche

Authenticated OS Command Injection in Contec CAN 2.0B Wireless LAN/USB Converter

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

An OS command injection flaw (CWE-78) exists in Contec's CAN 2.0B Communication Wireless LAN / USB Converter Unit, caused by improper neutralization of special elements used in an OS command. An attacker who can log in to the device — for example using default or low-privilege credentials — can inject and execute arbitrary operating system commands on the unit. Successful exploitation gives full control over the converter's underlying system with high impact to confidentiality, integrity, and availability (CVSS v4.0: 8.7), and could allow tampering with the CAN bus traffic the device bridges. Affected deployments are typically industrial, manufacturing, and automotive engineering environments that use these converters to relay CAN 2.0B traffic over wireless LAN or USB. No public proof-of-concept exists and the issue is not listed in CISA's KEV catalog, so exploitation is not known to be in the wild, though internet-exposed units with default credentials remain at meaningful risk.

What to do: Restrict the converter's login/management interface to trusted internal networks or VPN access and never expose it directly to the internet; replace any default or shared credentials with strong unique ones, since exploitation requires the attacker to log in. Check the Contec vendor advisory (via JPCERT, the assigning CNA) for a fixed firmware version and upgrade affected units when a patch is released. Monitor device behavior and logs for unexpected command execution or configuration changes indicative of compromise.

Affected
Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit
Estimated exposure
nicheLikely hundreds to low thousands of units deployed globally, with only a small subset internet-exposed (order of magnitude: ~10^3 or fewer exposed devices) — Based on deployment patterns for specialized industrial CAN-to-WLAN/USB converter hardware from a mid-sized Japanese vendor, which is purchased in small quantities per site and usually sits on internal industrial networks rather than being…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.