[Japanese]

JVNDB-2026-033234

Multiple vulnerabilities in Contec FLEXLAN series

Overview

FLEXLAN series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
  • OS command injection (CWE-78) - CVE-2026-82762, CVE-2026-82766
  • Cross-site scripting (CWE-79) - CVE-2026-82763, CVE-2026-82769, CVE-2026-82771
  • Cross-site request forgery (CWE-352) - CVE-2026-82764
  • Path traversal (CWE-23) - CVE-2026-82765, CVE-2026-82768
  • Cross-site scripting (CWE-79) - CVE-2026-82767
  • Buffer overflow (CWE-120) - CVE-2026-82770, CVE-2026-82772
Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.8 (High) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
The above CVSS base scores have been assigned for CVE-2026-82762, CVE-2026-82766


CVSS v3 Severity
Base Metrics:5.4 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82763, CVE-2026-82769, CVE-2026-82771


CVSS v3 Severity
Base Metrics:4.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82764


CVSS v3 Severity
Base Metrics:8.1 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82765, CVE-2026-82768


CVSS v3 Severity
Base Metrics:5.2 (Medium) [Other]
  • Access Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82767


CVSS v3 Severity
Base Metrics:8.8 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82770, CVE-2026-82772
Affected Products


Contec
  • ECE1000 versions prior to 1.02 (CVE-2026-82764, CVE-2026-82771, CVE-2026-82772)
  • ECE1020 versions prior to 1.02 (CVE-2026-82764, CVE-2026-82771, CVE-2026-82772)
  • ECS1020 versions prior to 1.02 (CVE-2026-82764, CVE-2026-82771, CVE-2026-82772)
  • FXA3000 versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA3000-[][] versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA3020 versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA3020-[][] versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA3200 versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA3200-[][] versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA5000 versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA5020 versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXA5020-[][] versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE3000 versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE3000-WP versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE3000-[][] versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE4000 versions prior to 1.14.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE4000-WP versions prior to 1.14.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE5000 versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXE5000-[][] versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXS300[]-CN versions prior to 1.20 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXS4000 versions prior to 1.14.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXS4020 versions prior to 1.14.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXS5000-[][] versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • FXS5021 versions prior to 1.12.00 (CVE-2026-82762, CVE-2026-82763, CVE-2026-82764, CVE-2026-82765)
  • RP-WAH-SR1 versions prior to 1.03 (CVE-2026-82764, CVE-2026-82769, CVE-2026-82770)
  • RP-WAH-SR12 versions prior to 1.02 (CVE-2026-82764, CVE-2026-82769, CVE-2026-82770)
  • RP-WAH-SR2 versions prior to 1.03 (CVE-2026-82764, CVE-2026-82769, CVE-2026-82770)
  • RP-WAH-SR22 versions prior to 1.02 (CVE-2026-82764, CVE-2026-82769, CVE-2026-82770)
  • SGA1000 versions prior to 1.02 (CVE-2026-82764, CVE-2026-82766, CVE-2026-82767, CVE-2026-82768)

Impact

  • An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-82762, CVE-2026-82766).
  • An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-82763, CVE-2026-82767, CVE-2026-82769, CVE-2026-82771).
  • If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed (CVE-2026-82764).
  • Arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP (CVE-2026-82765, CVE-2026-82768).
  • If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed (CVE-2026-82770, CVE-2026-82772).
Solution

[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
Vendor Information

Contec
CWE (What is CWE?)

  1. Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')(CWE-120) [Other]
  2. Relative Path Traversal(CWE-23) [Other]
  3. Cross-Site Request Forgery(CWE-352) [Other]
  4. OS Command Injection(CWE-78) [Other]
  5. Cross-site Scripting(CWE-79) [Other]
CVE (What is CVE?)

  1. CVE-2026-82762
  2. CVE-2026-82763
  3. CVE-2026-82764
  4. CVE-2026-82765
  5. CVE-2026-82766
  6. CVE-2026-82767
  7. CVE-2026-82768
  8. CVE-2026-82769
  9. CVE-2026-82770
  10. CVE-2026-82771
  11. CVE-2026-82772
References

  1. JVN : JVNVU#99009004
Revision History

  • [2026/09/14]
      Web page was published