CVE-2026-82791
nicheAuthenticated OS Command Injection in Contec CAN 2.0B Wireless LAN/USB Converter
An OS command injection flaw (CWE-78) exists in Contec's CAN 2.0B Communication Wireless LAN / USB Converter Unit, caused by improper neutralization of special elements used in an OS command. An attacker who can log in to the device — for example using default or low-privilege credentials — can inject and execute arbitrary operating system commands on the unit. Successful exploitation gives full control over the converter's underlying system with high impact to confidentiality, integrity, and availability (CVSS v4.0: 8.7), and could allow tampering with the CAN bus traffic the device bridges. Affected deployments are typically industrial, manufacturing, and automotive engineering environments that use these converters to relay CAN 2.0B traffic over wireless LAN or USB. No public proof-of-concept exists and the issue is not listed in CISA's KEV catalog, so exploitation is not known to be in the wild, though internet-exposed units with default credentials remain at meaningful risk.
What to do: Restrict the converter's login/management interface to trusted internal networks or VPN access and never expose it directly to the internet; replace any default or shared credentials with strong unique ones, since exploitation requires the attacker to log in. Check the Contec vendor advisory (via JPCERT, the assigning CNA) for a fixed firmware version and upgrade affected units when a patch is released. Monitor device behavior and logs for unexpected command execution or configuration changes indicative of compromise.
| Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.