|
[Japanese]
|
JVNDB-2026-032930
|
Multiple vulnerabilities in SolarView Compact
|
SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.- OS command injection in Schedule Settings (CWE-78) - CVE-2026-82794
- Cross-site scripting in Schedule Settings and Mail Send Setting (CWE-79) - CVE-2026-82795
- Cross-site scripting in Image Management (CWE-79) - CVE-2026-82796
Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
|
CVSS V3 Severity: Base Metrics 8.8 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2026-82794 |
CVSS v3 Severity Base Metrics:5.4 (Medium) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Confidentiality Impact(C): Low
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82795
|
CVSS v3 Severity Base Metrics:5.4 (Medium) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Confidentiality Impact(C): Low
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82796
|
|
Contec
- SolarView Compact SV-CPT-MC310 versions prior to 9.00
- SolarView Compact SV-CPT-MC310F versions prior to 9.00
|
|
- An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-82794).
- An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-82795, CVE-2026-82796).
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
|
Contec
|
- OS Command Injection(CWE-78) [Other]
- Cross-site Scripting(CWE-79) [Other]
|
- CVE-2026-82794
- CVE-2026-82795
- CVE-2026-82796
|
- JVN : JVNVU#97753461
|
- [2026/09/14]
Web page was published
|