Impact
Unrestricted upload of files with dangerous types is present in the CONPROSYS TM Series. A remote authenticated attacker who can upload a specially crafted file may trigger arbitrary command execution on the device. This weakness corresponds to improper handling of file types and grants attackers the ability to run code with the device’s privileges.
Affected Systems
The vulnerability affects three Contec Co., Ltd models: CPS‑TM341G5MB‑ADSC1‑931, CPS‑TM341GMB‑ADSC1‑931, and CPS‑TM341MB‑ADSC1‑931. No specific firmware or software versions are listed, implying that all current firmware releases of these models are potentially impacted.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is classified as High severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, yet the combination of authentication and clear attack path that can lead to remote command execution. The risk is elevated for any organization that allows authenticated users to interact with the device’s upload interface or who have not applied vendor fixes.
OpenCVE Enrichment