ZeroHour

CVE-2026-82794

moderate

Authenticated OS Command Injection in Contec SolarView Compact

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

SolarView Compact, an embedded gateway used to monitor solar power generation systems, contains an OS command injection flaw (CWE-78) in its Schedule Settings function. An attacker with valid login credentials to the product's web interface can inject arbitrary operating-system commands through the Schedule Settings parameters, which the device then executes. Successful exploitation gives the attacker full control of the appliance, turning it into a foothold in the energy-monitoring or OT network it sits on — reflected in the high CVSS 4.0 score of 8.7 (network vector, low privileges required). Organizations running SolarView Compact, especially units reachable from the internet or shared networks, are affected. No public proof-of-concept or confirmed in-the-wild exploitation has been reported and the flaw is not in CISA's KEV catalog, though SolarView Compact has previously been a favored target via a similar command injection flaw (CVE-2023-23333) used in botnet and ransomware campaigns.

What to do: Apply Contec's fixed firmware as soon as vendor guidance is available and verify your device version against the advisory. Because exploitation requires a valid login, remove the SolarView Compact web interface from the internet, restrict it to a VPN or management VLAN, and enforce strong unique credentials while deleting unused accounts. Audit Schedule Settings and device logs for unexplained scheduled commands or configuration changes that could indicate tampering.

Affected
Contec SolarView Compact
Estimated exposure
moderate≈1,000–3,000 internet-exposed devices, plus an unknown number on internal networks — Public internet-wide scans at the time of a prior SolarView Compact flaw (CVE-2023-23333) consistently showed on the order of 2,000 exposed units, and this CVE affects the same narrow, industrial-monitoring device population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.