Impact
A buffer overflow flaw exists in the Contec RP-WAH-SR Series. When a remote attacker sends a carefully crafted request to the device’s web service, the overflow can be triggered, allowing arbitrary code execution with the privileges of the web service process. The issue is a classic writer without bounds error (CWE‑120) that can lead to full system compromise if exploited.
Affected Systems
Contec Co., Ltd. manufactures the RP-WAH‑SR1, RP-WAH‑SR12, RP-WAH‑SR2 and RP-WAH‑SR22 models that are vulnerable. No specific firmware versions are listed, so all releases of the affected series may be impacted.
Risk and Exploitability
The CVSS score of 8.7 classifies this as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the flaw can be activated remotely through the web service interface, making it potentially exploitable without user interaction. An attacker would need network access to the device and the ability to send HTTP requests to the vulnerable endpoint, after which the attacker could execute arbitrary code on the device.
OpenCVE Enrichment