Description
Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthorized control via REST API
Action: Immediate Patch
AI Analysis

Impact

An attacker can invoke critical REST API functions on the Contec Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* without authentication, allowing them to read I/O values or command outputs. The vulnerability is a Missing Authentication flaw (CWE-306) and is scored with a CVSS of 6.9, indicating moderate severity and potential impacts to confidentiality, integrity and availability.

Affected Systems

The affected product is Contec Co., Ltd.'s Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* - all models in the series are impacted, no specific firmware or software version is listed.

Risk and Exploitability

The EPSS score is 0.00201, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet; however, the CVSS of 6.9 reflects moderate risk. The flaw is exploitable remotely over the network via the exposed REST API with no authentication required. A remote attacker could potentially retrieve sensitive data or disrupt operation by manipulating I/O outputs.

Generated by OpenCVE AI on September 15, 2026 at 15:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the security update provided in Contec's 2026-09-10 security notice as described in the PDF link.
  • Configure the device to enforce authentication on all REST API endpoints, addressing the Missing Authentication flaw (CWE-306).
  • Restrict network access to the device’s REST API by using firewalls, VPNs or IP whitelists, ensuring only trusted systems can contact it.
  • If the API is not needed, disable or block the vulnerable endpoints to eliminate exposure.

Generated by OpenCVE AI on September 15, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec remote I/o Coupler Unit (server Type) Cpsn-mcb271-*
Vendors & Products Contec
Contec remote I/o Coupler Unit (server Type) Cpsn-mcb271-*

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Missing Authentication in REST API Enables Remote Read/Control of I/O Coupler

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Missing Authentication in REST API Enables Remote Read/Control of I/O Coupler

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Contec Remote I/o Coupler Unit (server Type) Cpsn-mcb271-*
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.275Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82784

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:03.073Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:20.230

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:58Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function