Impact
This vulnerability allows a remote authenticated attacker to upload a specially crafted file with a dangerous type to a Contec CAN‑2‑USB or CAN‑2‑WF Wireless LAN/USB converter. The device accepts and processes the file without validating its content or type, which can lead to arbitrary code execution on the converter. The flaw is classified as CWE‑434. The consequence is a total loss of confidentiality, integrity, and availability of the impacted device.
Affected Systems
Contec Co., Ltd.’s CAN‑2‑USB and CAN‑2‑WF Wireless LAN/USB converter units are affected. No firmware version range is specified in the advisory, meaning all current or older units that have not applied the later firmware release remain vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is below 1%, suggesting a low probability of exploitation at the present time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote authenticated; an adversary would need valid credentials to access the device endpoint.
OpenCVE Enrichment