|
[Japanese]
|
JVNDB-2026-032931
|
Multiple vulnerabilities in Contec PC-HELPER series
|
PC-HELPER series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.- Cross-site scripting (CWE-79) - CVE-2026-82790
- Cross-site request forgery (CWE-352) - CVE-2026-82764
- OS command injection (CWE-78) - CVE-2026-82791
- Cross-site scripting (CWE-79) - CVE-2026-82792
- Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82793
Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
|
CVSS V3 Severity: Base Metrics 5.4 (Medium) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2026-82790 |
CVSS v3 Severity Base Metrics:4.3 (Medium) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact(C): None
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82764
|
CVSS v3 Severity Base Metrics:8.8 (High) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82791
|
CVSS v3 Severity Base Metrics:5.2 (Medium) [Other]- Access Vector: Adjacent Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Confidentiality Impact(C): Low
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82792
|
CVSS v3 Severity Base Metrics:7.2 (High) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): High
- Integrity Impact(I): High
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82793
|
|
Contec
- CAN 2.0B Communication Wireless LAN / USB Converter Unit CAN-2-USB versions prior to 2.20 (CVE-2026-82791, CVE-2026-82792, CVE-2026-82793)
- CAN 2.0B Communication Wireless LAN / USB Converter Unit CAN-2-WF versions prior to 2.20 (CVE-2026-82791, CVE-2026-82792, CVE-2026-82793)
- PC-HELPER Wireless I/O DIO-0404RY-LWF versions prior to 1.01.00 (CVE-2026-82790, CVE-2026-82764)
- PC-HELPER Wireless I/O DIO-0404RY-LWF-US versions prior to 1.01.00 (CVE-2026-82790, CVE-2026-82764)
|
|
- An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-82790, CVE-2026-82792).
- If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed (CVE-2026-82764).
- An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-82791)
- If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product (CVE-2026-82793).
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
|
Contec
|
- Cross-Site Request Forgery(CWE-352) [Other]
- Unrestricted Upload of File with Dangerous Type(CWE-434) [Other]
- OS Command Injection(CWE-78) [Other]
- Cross-site Scripting(CWE-79) [Other]
|
- CVE-2026-82764
- CVE-2026-82790
- CVE-2026-82791
- CVE-2026-82792
- CVE-2026-82793
|
- JVN : JVNVU#90314828
|
- [2026/09/14]
Web page was published
|