Impact
A buffer overflow flaw exists in the web service component of Contec EC1000 series devices. When a remote attacker sends a specially crafted request, the overflow can allow arbitrary program execution on the target system. The vulnerability is a classic out‑of‑bounds write (CWE‑120) and can compromise confidentiality, integrity, availability, and potentially systemwide control if exploited.
Affected Systems
Contec Co., Ltd. devices: EC1000, EC1020, and ECS1020 models are affected. Specific firmware or software version data are not supplied in the advisory.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while EPSS data is unavailable there is no indication of low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description the attack vector is remote via the exposed web service; the attacker requires network access to the device and the ability to craft a malicious payload to trigger the overflow.
OpenCVE Enrichment