Impact
The identified vulnerability is an OS command injection flaw in Contec’s CONPROSYS M2M Gateway and Controller series. An attacker who can authenticate to the device may supply specially crafted input that is executed by the operating system, allowing arbitrary commands to run. This provides the attacker with full control over the device, potentially enabling data exfiltration, device takeover, or pivoting to other network assets. The weakness is catalogue as CWE‑78, which describes failures to properly filter or escape user‑supplied command strings.
Affected Systems
Affected products include the Contec M2M Controller Configurable type CPS‑MCS341*, Integrated type CPS‑MC341, M2M Gateway Configurable type CPS‑MGS341*, and Integrated type CPS‑MG341*. No specific firmware or software version information is supplied, so all variants of the listed models are potentially vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity with significant impact. Exploitation requires an authenticated session, so the threat is limited to accounts with access to the device. The EPSS score of 1% indicates a low but nonzero exploitation probability, and the vulnerability is not listed in KEV, so while publicly documented exploitation remains uncertain, the high CVSS suggests that if the vulnerability is discovered, attackers could mount a powerful attack. The official security advisory linked in the references recommends a firmware update to remediate the issue.
OpenCVE Enrichment