Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-09-14
Score: 8.7 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Command Execution
Action: Patch ASAP
AI Analysis

Impact

Improper neutralization of special elements used in an OS command allows an attacker who can log into the CONPROSYS PAC Series to execute arbitrary system commands. This flaw can be leveraged to gain full control of the device, exfiltrate data, or disrupt services, thereby compromising confidentiality, integrity, and availability. The weakness is an OS command injection, classified as CWE‑78.

Affected Systems

The vulnerability affects Contec Co., Ltd. products PCS341[][]‑DS1‑1201 and the Integrated Type CPS‑PC341[][]‑*-9201. No specific firmware version information is provided, so all current models in use should be considered potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, and the EPSS score of 1% suggests a low but non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to require authenticated access, as an attacker must log into the device to supply the malicious input. Once authenticated, the attacker can run arbitrary OS commands.

Generated by OpenCVE AI on September 14, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply the latest device firmware update that addresses the OS command injection flaw.
  • Restrict or disable remote access to the device and enforce strong authentication to limit the ability of an attacker to log in.
  • Configure the device (or its web/management interface) to validate or sanitize any user-supplied input before it is passed to system commands, following standard input‑validation practices for preventing command injection.

Generated by OpenCVE AI on September 14, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in CONPROSYS PAC Series Allowing Remote Command Execution

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in CONPROSYS PAC Series Allowing Remote Command Execution

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:48.534Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82777

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:17.616Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:19.247

Modified: 2026-09-14T12:17:47.967

Link: CVE-2026-82777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T21:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')