CVE-2026-82793
nicheAuthenticated File-Upload RCE in Contec CAN 2.0B Wireless LAN / USB Converter
CVE-2026-82793 is an unrestricted file upload vulnerability (CWE-434) in Contec's CAN 2.0B Communication Wireless LAN / USB Converter Unit, a device that bridges CAN bus traffic onto wireless or USB-connected networks. A remote attacker who already holds valid (high-privilege) authentication credentials can upload a specially crafted file of a dangerous type, and the product will accept and process it, resulting in execution of arbitrary code on the converter itself. Successful exploitation gives the attacker full control of the device (high impact to confidentiality, integrity, and availability), which could allow manipulation of CAN bus traffic passing through the converter or use of the device as a foothold in an industrial or automotive network. The CVSS 4.0 score is 8.6 (high), but exploitation requires existing credentials, so exposed devices with weak or default accounts on reachable management interfaces are the primary risk. There is no known public proof of concept, the flaw is not on the CISA KEV catalog, and no exploitation in the wild has been reported as of this analysis.
What to do: Check the Contec and JPCERT advisories for this CVE and apply any firmware update as soon as one is available. In the meantime, remove the converter's management/upload interface from internet exposure, restrict it to an isolated industrial network segment, and enforce strong unique credentials since the flaw requires authentication. Audit device accounts for default or shared credentials and monitor device logs for unexpected file uploads or configuration changes.
| Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.