Impact
The vulnerability is an OS command injection that occurs because the device fails to neutralize special characters used in operating‑system commands. An attacker who can log into the Contec CPS series can supply arbitrary input that is executed directly by the underlying OS, enabling remote code execution and full compromise of the device.
Affected Systems
Affected hardware includes Contec Co., Ltd CPS-TM341G5MB-ADSC1-931, CPS-TM341GMB-ADSC1-931, and CPS-TM341MB-ADSC1-931. No specific firmware revisions are listed in the advisory; all models identified in the CNA entry are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of 1% indicates a low but non‑zero exploitation probability, and the issue is not listed in CISA's KEV catalog. The vulnerability requires the attacker to be authenticated on the device; accordingly, successful exploitation is limited to users with legitimate login credentials, allowing them to execute arbitrary OS commands and fully compromise the device.
OpenCVE Enrichment