Description
SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-09-14
Score: 8.7 High
EPSS: 1.9% Low
KEV: No
Impact: Remote OS Command Execution
Action: Assess Impact
AI Analysis

Impact

SolarView Compact Schedule Settings feature allows a log‑in user to submit crafted input that is executed as an operating system command, enabling the operator to run arbitrary code on the device. The vulnerability directly compromises confidentiality, integrity, and availability by allowing an attacker to potentially gain full control score of 8.7 classifies the issue as high severity. The EPSS score of 1% indicates that the probability of exploitation is low but non‑zero, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires authenticated access, meaning any user that can log in may exploit it once credentials are obtained.

Affected Systems

Contec SolarView Compact models SV-CPT-MC310 and SV-CPT-MC310F are affected. The flaw resides in the web interface accessed after authentication, meaning any user who can log in may potentially exploit it.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the EPSS score of 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires authenticated access crafted input to the schedule settings, resulting in arbitrary OS command execution. This enables remote code execution on the device, potentially allowing full system compromise.

Generated by OpenCVE AI on September 15, 2026 at 15:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Consult Contec's security advisory for potential updates and apply any available firmware or software patch.
  • Ensure that only trusted personnel possess login credentials and consider enabling multi‑factor authentication if the device supports it.
  • Limit network exposure of the SolarView Compact by restricting access to known IP ranges and monitoring for suspicious command execution attempts.

Generated by OpenCVE AI on September 15, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title SolarView Compact OS Command Injection in Schedule Settings

Mon, 14 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in SolarView Compact Schedule Settings

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in SolarView Compact Schedule Settings

Mon, 14 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec sv-cpt-mc310
Contec sv-cpt-mc310f
Vendors & Products Contec
Contec sv-cpt-mc310
Contec sv-cpt-mc310f

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Contec Sv-cpt-mc310 Sv-cpt-mc310f
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:38:27.626Z

Reserved: 2026-08-31T02:30:58.279Z

Link: CVE-2026-82794

cve-icon Vulnrichment

Updated: 2026-09-14T11:36:39.852Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:21.617

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')