Impact
The flaw allows an attacker that can log into the device to inject arbitrary operating system commands through unsanitized input. This is a classic OS command injection vulnerability, classified as CWE-78. causing loss of confidentiality, integrity, and availability. The product in question is the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit, and the advisory does not list affected firmware builds, so all current releases may be vulnerable until a patch is applied.
Affected Systems
The vulnerability affects Contec Co., Ltd.'s CAN-2-USB and CAN-2-WF models. These are adapters that enable CAN 2.0B communication over USB or wireless LAN, respectively. Any installation of these units with Contec's firmware may be susceptible to exploitation.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, but the EPSS score of 1% reflects low exploitation probability. The vulnerability is not in the CISA KEV catalog, indicating no publicly reported exploitation yet. Nonetheless, because the flaw only requires legitimate credentials, authentication controls remain critical to mitigate risk.
OpenCVE Enrichment