Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-09-14
Score: 8.7 High
EPSS: 1.2% Low
KEV: No
Impact: Remote command execution
Action: Immediate patch
AI Analysis

Impact

The identified vulnerability is an OS command injection flaw in Contec’s CONPROSYS M2M Gateway and Controller series. An attacker who can authenticate to the device may supply specially crafted input that is executed by the operating system, allowing arbitrary commands to run. This provides the attacker with full control over the device, potentially enabling data exfiltration, device takeover, or pivoting to other network assets. The weakness is catalogue as CWE‑78, which describes failures to properly filter or escape user‑supplied command strings.

Affected Systems

Affected products include the Contec M2M Controller Configurable type CPS‑MCS341*, Integrated type CPS‑MC341, M2M Gateway Configurable type CPS‑MGS341*, and Integrated type CPS‑MG341*. No specific firmware or software version information is supplied, so all variants of the listed models are potentially vulnerable until a vendor update is applied.

Risk and Exploitability

The CVSS base score of 8.7 indicates a high severity with significant impact. Exploitation requires an authenticated session, so the threat is limited to accounts with access to the device. The EPSS score of 1% indicates a low but nonzero exploitation probability, and the vulnerability is not listed in KEV, so while publicly documented exploitation remains uncertain, the high CVSS suggests that if the vulnerability is discovered, attackers could mount a powerful attack. The official security advisory linked in the references recommends a firmware update to remediate the issue.

Generated by OpenCVE AI on September 14, 2026 at 20:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the firmware update published by Contec in the security advisory linked on the vendor website; the update contains the patch for the OS command injection flaw.
  • Enforce strong authentication: ensure that only privileged users can log in to the device and consider disabling default or weak credentials.
  • Restrict administrative access to the device by placing it on a separate network segment or applying firewall rules that limit inbound connections to trusted IP addresses.
  • Regularly review device logs for unusual command execution activity and set up alerts for suspicious entries.

Generated by OpenCVE AI on September 14, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Contec M2M Gateway and Controller Series

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:49.071Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82774

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:23.552Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:18.833

Modified: 2026-09-14T12:17:47.610

Link: CVE-2026-82774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T20:30:08Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')