Description
Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A stack-based buffer overflow flaw exists in the Remote I/O Coupler Unit (Server Type) CPSN‑MCB271‑*. When a remote attacker sends a specially crafted request, the overflow can corrupt the local stack and lead to a denial‑of‑service condition. This vulnerability falls under CWE‑121 and permits an attacker to terminate the service without compromising confidentiality or integrity of data.

Affected Systems

The issue affects Contec Co., Ltd. Remote I/O Coupler Units of the Server Type, specifically any model matching The product runs on the device’s embedded firmware and is intended for remote control and monitoring functions.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, and the EPSS score is <1%. The vulnerability is not listed in CISA’s KEV catalog. Although exploitation requires remote network access and the ability to send a crafted packet, no public exploit code has been disclosed. The likely attack vector is remote network-based intrusion targeting exposed service endpoints, and mitigation hinges on applying the firmware update released by Contec.

Generated by OpenCVE AI on September 14, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download the latest firmware update from Contec’s security page (https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf).
  • Install the new firmware on all affected CPSN‑MCB271‑* units.
  • Reboot each device after the update to ensure the patch takes effect.

Generated by OpenCVE AI on September 14, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow Causing Denial of Service in Remote I/O Coupler Unit

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.105Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82785

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:59.808Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:20.370

Modified: 2026-09-14T12:17:48.937

Link: CVE-2026-82785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T21:30:08Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow