Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-09-14
Score: 8.7 High
EPSS: 1.9% Low
KEV: No
Impact: Remote command execution
Action: Immediate patch
AI Analysis

Impact

The vulnerability is an OS command injection flaw in Contec’s CONPROSYS M2M Gateway and Controller series. Because the application fails to neutralize special elements used in an OS command, an attacker who can log in to a device can supply crafted input that the operating system executes. This allows the attacker to run arbitrary commands with the privileges of the firmware process, yielding full control over the affected device, data exfiltration, or lateral movement.

Affected Systems

Affected products include Contec M2M Controller Configurable type CPS‑MCS341*, Integrated type CPS‑MC341, M2M Gateway Configurable type CPS‑MGS341*, and Integrated type CPS‑MG341*. The advisory notes that no firmware or software version information is supplied, so all current iterations of the listed models are considered potentially vulnerable until a vendor update is applied.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity; the vulnerability is limited to authenticated sessions, so compromised credentials or default accounts are required. The EPSS score of 1% shows a low CISA KEV, meaning no known active exploitation has been reported. The official advisory recommends a firmware update to remediate the issue; until then, the risk remains significant if an attacker gains authentication.

Generated by OpenCVE AI on September 15, 2026 at 15:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the firmware patch released validation defect that causes the command injection.
  • Enforce strong, unique authentication for device access; disable default or weak credentials and use role‑based permissions to limit who can log in.
  • Isolate the devices from external networks by placing them on a dedicated segment or applying firewall rules that restrict inbound connections to trusted IP ranges.
  • Monitor system logs for unexpected command execution and configure alerts for suspicious activity to detect exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec m2m Controller Configurable Type Cps-mcs341*
Contec m2m Controller Integrated Type Cps-mc341
Contec m2m Gateway Configurable Type Cps-mgs341*
Contec m2m Gateway Integrated Type Cps-mg341*
Vendors & Products Contec
Contec m2m Controller Configurable Type Cps-mcs341*
Contec m2m Controller Integrated Type Cps-mc341
Contec m2m Gateway Configurable Type Cps-mgs341*
Contec m2m Gateway Integrated Type Cps-mg341*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Contec M2M Gateway and Controller Series

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Contec M2M Gateway and Controller Series

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Contec M2m Controller Configurable Type Cps-mcs341* M2m Controller Integrated Type Cps-mc341 M2m Gateway Configurable Type Cps-mgs341* M2m Gateway Integrated Type Cps-mg341*
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:49.071Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82774

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:23.552Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:18.833

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')