Impact
The vulnerability is an OS command injection flaw in Contec’s CONPROSYS M2M Gateway and Controller series. Because the application fails to neutralize special elements used in an OS command, an attacker who can log in to a device can supply crafted input that the operating system executes. This allows the attacker to run arbitrary commands with the privileges of the firmware process, yielding full control over the affected device, data exfiltration, or lateral movement.
Affected Systems
Affected products include Contec M2M Controller Configurable type CPS‑MCS341*, Integrated type CPS‑MC341, M2M Gateway Configurable type CPS‑MGS341*, and Integrated type CPS‑MG341*. The advisory notes that no firmware or software version information is supplied, so all current iterations of the listed models are considered potentially vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity; the vulnerability is limited to authenticated sessions, so compromised credentials or default accounts are required. The EPSS score of 1% shows a low CISA KEV, meaning no known active exploitation has been reported. The official advisory recommends a firmware update to remediate the issue; until then, the risk remains significant if an attacker gains authentication.
OpenCVE Enrichment