Impact
An attacker can invoke critical REST API functions on the Contec Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* without authentication, allowing them to read I/O values or command outputs. The vulnerability is a Missing Authentication flaw (CWE‑306) and is scored with a CVSS of 6.9, indicating moderate severity and potential impacts to confidentiality, integrity, and availability.
Affected Systems
The affected product is Contec Co., Ltd.’s Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. All models matching that series are impacted; no specific firmware or software version is listed.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet; however, the CVSS of 6.9 reflects moderate risk. The flaw is exploitable remotely over the network via the exposed REST API with no authentication required. A remote attacker could potentially retrieve sensitive data or disrupt operation by manipulating I/O outputs.
OpenCVE Enrichment