Description
Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthorized control via REST API
Action: Immediate Patch
AI Analysis

Impact

An attacker can invoke critical REST API functions on the Contec Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* without authentication, allowing them to read I/O values or command outputs. The vulnerability is a Missing Authentication flaw (CWE‑306) and is scored with a CVSS of 6.9, indicating moderate severity and potential impacts to confidentiality, integrity, and availability.

Affected Systems

The affected product is Contec Co., Ltd.’s Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. All models matching that series are impacted; no specific firmware or software version is listed.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet; however, the CVSS of 6.9 reflects moderate risk. The flaw is exploitable remotely over the network via the exposed REST API with no authentication required. A remote attacker could potentially retrieve sensitive data or disrupt operation by manipulating I/O outputs.

Generated by OpenCVE AI on September 14, 2026 at 10:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official security patch or update released by Contec (see the 2026‑09‑10 security notice).
  • Restrict network access to the REST API by configuring firewalls, VPNs, or IP whitelists so that only trusted systems can reach the device.
  • If the API is not required, disable or block the vulnerable endpoints or enable mandatory authentication in the device configuration.

Generated by OpenCVE AI on September 14, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.275Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82784

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:03.073Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:20.230

Modified: 2026-09-14T12:17:48.810

Link: CVE-2026-82784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T10:45:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function