Impact
The vulnerability arises when a critical function on the Contec CPSL‑08P1EN device operates without any authentication. An attacker who can reach the device over the network may invoke this function and gain full control of the equipment, potentially leading to service disruption. The weakness is identified as CWE‑306, which represents missing authentication and thus undermines the integrity and availability of the system.
Affected Systems
All installations of the Contec CPSL‑08P1EN device are affected. No specific version information is available, so every deployment of this hardware should be treated as vulnerable until proven otherwise.
Risk and Exploitability
The CVSS score of 8.7 marks this issue as high severity, indicating that exploitation would provide a significant impact to the device. The EPSS score of < 1% indicates a very low probability of exploitation in the wild. Although the vulnerability is not listed in the CISA KEV catalog, the risk remains substantial because the impact is high and the attack vector is remote. Based on the description, the attack vector is likely remote and does not require prior authentication, meaning that any actor with network access to the device could exploit it.
OpenCVE Enrichment