Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-09-14
Score: 8.7 High
EPSS: 1.9% Low
KEV: No
Impact: OS Command Execution
Action: Patch Now
AI Analysis

Impact

The flaw allows an attacker that can log into the device to inject arbitrary operating system commands through unsanitized input. This is a classic OS command injection vulnerability, classified as CWE-78. causing loss of confidentiality, integrity, and availability. The product in question is the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit, and the advisory does not list affected firmware builds, so all current releases may be vulnerable until a patch is applied.

Affected Systems

The vulnerability affects Contec Co., Ltd.'s CAN-2-USB and CAN-2-WF models. These are adapters that enable CAN 2.0B communication over USB or wireless LAN, respectively. Any installation of these units with Contec's firmware may be susceptible to exploitation.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, but the EPSS score of 1% reflects low exploitation probability. The vulnerability is not in the CISA KEV catalog, indicating no publicly reported exploitation yet. Nonetheless, because the flaw only requires legitimate credentials, authentication controls remain critical to mitigate risk.

Generated by OpenCVE AI on September 15, 2026 at 15:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update provided by Contec to remedy the OS command injection flaw.
  • Replace default or weak credentials on the device to reduce the likelihood of an attacker gaining authenticated access.
  • Restrict device connectivity to a trusted management network and enforce strict firewall rules to limit exposure to untrusted hosts.

Generated by OpenCVE AI on September 15, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec can-2-usb
Contec can-2-wf
Vendors & Products Contec
Contec can-2-usb
Contec can-2-wf

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection Vulnerability in Contec CAN 2.0B Converter Unit

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Contec CAN‑2‑USB/WF Converter Allowing Remote Command Execution

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Contec CAN‑2‑USB/WF Converter Allowing Remote Command Execution

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Contec Can-2-usb Can-2-wf
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T12:07:55.617Z

Reserved: 2026-08-31T02:30:58.279Z

Link: CVE-2026-82791

cve-icon Vulnrichment

Updated: 2026-09-14T12:07:50.467Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:21.203

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:40Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')