Description
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Remote Access
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises when a critical function on the Contec CPSL‑08P1EN device operates without any authentication. An attacker who can reach the device over the network may invoke this function and gain full control of the equipment, potentially leading to service disruption. The weakness is identified as CWE‑306, which represents missing authentication and thus undermines the integrity and availability of the system.

Affected Systems

All installations of the Contec CPSL‑08P1EN device are affected. No specific version information is available, so every deployment of this hardware should be treated as vulnerable until proven otherwise.

Risk and Exploitability

The CVSS score of 8.7 marks this issue as high severity, indicating that exploitation would provide a significant impact to the device. The EPSS score of < 1% indicates a very low probability of exploitation in the wild. Although the vulnerability is not listed in the CISA KEV catalog, the risk remains substantial because the impact is high and the attack vector is remote. Based on the description, the attack vector is likely remote and does not require prior authentication, meaning that any actor with network access to the device could exploit it.

Generated by OpenCVE AI on September 15, 2026 at 15:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update or security patch for the CPSL‑08P1EN device as documented in Contec’s 2026 security release
  • Disable the exposed critical function through the device’s configuration interface, if the option exists, until a patch becomes available
  • Restrict network access to the device by placing it behind a firewall or physically isolating it from untrusted networks, and monitor for unauthorized communication attempts

Generated by OpenCVE AI on September 15, 2026 at 15:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec cpsl-08p1en
Vendors & Products Contec
Contec cpsl-08p1en

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Missing Authentication Enabling Remote Control of Contec CPSL‑08P1EN Device

Mon, 14 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Access via Missing Authentication in Contec CPSL‑08P1EN

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Remote Access via Missing Authentication in Contec CPSL‑08P1EN

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Contec Cpsl-08p1en
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:46.587Z

Reserved: 2026-08-31T02:30:58.279Z

Link: CVE-2026-82787

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:53.642Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:20.660

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:47Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function