Impact
Unrestricted upload of files with dangerous types is present in the CONPROSYS TM Series. A remote authenticated attacker who uploads a specially crafted file may trigger arbitrary command execution on the device, allowing the attacker to run code with the device’s privileges.
Affected Systems
The vulnerability affects three Contec Co., Ltd models: CPS‑TM341G5MB‑ADSC1‑931, CPS‑TM341GMB‑ADSC1‑931, and CPS‑TM341MB‑ADSC1‑931. No specific firmware or software versions are listed, implying that all current firmware releases of these models are potentially impacted.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is classified as High severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The combination of authentication and a clear attack path that can lead to remote command execution makes the risk elevated for any organization that allows authenticated users to interact with the device’s upload interface or who have not applied vendor fixes.
OpenCVE Enrichment