Published:2026/09/10  Last Updated:2026/09/10

JVNVU#96551518
Multiple vulnerabilities in Contec CONPROSYS series

Overview

CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities.

Products Affected

CVE-2026-82773, CVE-2026-82774, CVE-2026-82775, CVE-2020-7746

  • CONPROSYS M2M Gateway Series
    • M2M Gateway Integrated Type CPS-MG341* versions prior to 4.1.0
    • M2M Gateway Configurable type CPS-MGS341* versions prior to 4.1.0
  • CONPROSYS M2M Controller Series
    • M2M Controller Integrated Type CPS-MC341 versions prior to 4.1.0
    • M2M Controller Configurable type CPS-MCS341* versions prior to 4.1.0
CVE-2026-82776, CVE-2026-82777, CVE-2026-82778, CVE-2020-7746
  • CONPROSYS PAC Series
    • Integrated Type CPS-PC341[][]-*-9201 versions prior to 3.0.0
    • Configurable type CPS-PCS341[][]-DS1-1201 versions prior to 3.0.0
CVE-2026-82779, CVE-2026-82780, CVE-2020-7746
  • CONPROSYS TM Series
    • CPS-TM341G5MB-ADSC1-931 versions prior to 2.19
    • CPS-TM341MB-ADSC1-931 versions prior to 2.19
    • CPS-TM341GMB-ADSC1-931 2.19
CVE-2026-82781, CVE-2026-82782, CVE-2026-82764, CVE-2026-82783
  • CONPROSYS nano Series
    • Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* versions prior to 1.82
    • Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 versions prior to 1.02
    • Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041 versions prior to 1.61
CVE-2026-82784, CVE-2026-82785, CVE-2026-82786
  • CONPROSYS nano Series
    • Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* versions prior to 1.82
CVE-2026-82787, CVE-2026-82788, CVE-2020-7746
  • CONPROSYS IO-Link Master
    • CPSL-08P1EN versions prior to 2.3.10
CVE-2026-82789
  • CONPROSYS HMI System(CHS) versions prior to 3.8.0

Description

CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.

  • Cross-site scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 5.1
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score 6.1
    • CVE-2026-82773, CVE-2026-82776, CVE-2026-82788
  • OS command injection (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-82774, CVE-2026-82777, CVE-2026-82779
  • Exposure of information through directory listing (CWE-548)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 5.3
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Base Score 4.3
    • CVE-2026-82775, CVE-2026-82778
  • Dependency on vulnerable third-party component (CWE-1395)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 7.1
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
    • This issue is caused by a vulnerability in chart.js (CVE-2020-7746).
  • Unrestricted upload of file with dangerous type (CWE-434)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-82780
  • Cross-site scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 5.1
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Base Score 5.4
    • CVE-2026-82781
  • Out-of-bounds write (CWE-787)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Base Score 5.3
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Base Score 4.3
    • CVE-2026-82782
  • Cross-site request forgery (CWE-352)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Base Score 4.3
    • CVE-2026-82764
  • Plaintext storage of a password (CWE-256)
    • CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 4.1
    • CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 4.2
    • CVE-2026-82783
  • Missing authentication for critical function (CWE-306)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5
    • CVE-2026-82784
  • Stack-based buffer overflow (CWE-121)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Base Score 5.3
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Base Score 4.3
    • CVE-2026-82785
  • Insufficiently protected credentials (CWE-522)
    • CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 8.2
    • CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Base Score: 6.3
    • CVE-2026-82786
  • Missing authentication for critical function (CWE-306)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score: 8.7
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score: 9.8
    • CVE-2026-82787
  • Eval injection (CWE-95)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score: 8.7
    • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score: 8.8
    • CVE-2026-82789

Impact

  • An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-82773, CVE-2026-82776, CVE-2026-82781, CVE-2026-82788).
  • An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-82774, CVE-2026-82777, CVE-2026-82779).
  • Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication (CVE-2026-82775, CVE-2026-82778).
  • A denial-of-service (DoS) condition may be caused by an attacker (CVE-2020-7746).
  • If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product (CVE-2026-82780).
  • Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition (CVE-2026-82782, CVE-2026-82785).
  • If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed (CVE-2026-82764)
  • An attacker with physical access to the product may obtain credentials (CVE-2026-82783).
  • An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output (CVE-2026-82784).
  • Sensitive information may be restored from a backup file (CVE-2026-82786).
  • An affected product may be operated by a remote attacker without authentication (CVE-2026-82787).
  • Arbitrary code may be executed by an attacker who can log in to the product (CVE-2026-82789).

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.