Impact
A buffer overflow flaw exists in the web service component of Contec EC1000 series devices. When a remote attacker sends a specially crafted request, the overflow allows arbitrary program execution on the target system. The vulnerability is a classic out‑of‑bounds write (CWE‑120) that can compromise confidentiality, integrity, availability, and potentially grant systemwide control if exploited.
Affected Systems
Contec Co., Ltd. devices: ECE1000, ECE1020, and ECS1020 models are affected. Specific firmware or software version data are not supplied in the advisory.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in CISA KEV. The attack vector is remote via the exposed web service; an attacker requires network access to the device and the ability to craft a malicious payload to trigger the overflow.
OpenCVE Enrichment