[Japanese]

JVNDB-2026-033235

Multiple vulnerabilities in Contec CONPROSYS series

Overview

CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
  • Cross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788
  • OS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779
  • Exposure of information through directory listing (CWE-548) - CVE-2026-82775, CVE-2026-82778
  • Dependency on vulnerable third-party component (CWE-1395)
    • This issue is caused by a vulnerability in chart.js (CVE-2020-7746).
  • Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-82780
  • Cross-site scripting (CWE-79) - CVE-2026-82781
  • Out-of-bounds write (CWE-787) - CVE-2026-82782
  • Cross-site request forgery (CWE-352) - CVE-2026-82764
  • Plaintext storage of a password (CWE-256) - CVE-2026-82783
  • Missing authentication for critical function (CWE-306) - CVE-2026-82784
  • Stack-based buffer overflow (CWE-121) - CVE-2026-82785
  • Insufficiently protected credentials (CWE-522) - CVE-2026-82786
  • Missing authentication for critical function (CWE-306) - CVE-2026-82787
  • Eval injection (CWE-95) - CVE-2026-82789
Contec Co., Ltd. reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.1 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2026-82773, CVE-2026-82776, CVE-2026-82788


CVSS v3 Severity
Base Metrics:8.8 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82774, CVE-2026-82777, CVE-2026-82779


CVSS v3 Severity
Base Metrics:4.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): None
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82775, CVE-2026-82778


CVSS v3 Severity
Base Metrics:7.5 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): None
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2020-7746


CVSS v3 Severity
Base Metrics:8.8 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82780


CVSS v3 Severity
Base Metrics:5.4 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82781


CVSS v3 Severity
Base Metrics:4.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): None
  • Availability Impact(A): Low
The above CVSS base scores have been assigned for CVE-2026-82782


CVSS v3 Severity
Base Metrics:4.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82764


CVSS v3 Severity
Base Metrics:4.2 (Medium) [Other]
  • Access Vector: Physical
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): None
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82783


CVSS v3 Severity
Base Metrics:6.5 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82784


CVSS v3 Severity
Base Metrics:4.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): None
  • Availability Impact(A): Low
The above CVSS base scores have been assigned for CVE-2026-82785


CVSS v3 Severity
Base Metrics:6.3 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact(C): High
  • Integrity Impact(I): None
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-82786


CVSS v3 Severity
Base Metrics:9.8 (Critical) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82787


CVSS v3 Severity
Base Metrics:8.8 (High) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): High
  • Integrity Impact(I): High
  • Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-82789
Affected Products


Contec
  • CONPROSYS HMI System (CHS) versions prior to 3.8.0 (CVE-2026-82789)
  • CPS-TM341G5MB-ADSC1-931 versions prior to 2.19 (CVE-2026-82779, CVE-2026-82780, CVE-2020-7746)
  • CPS-TM341GMB-ADSC1-931 2.19 (CVE-2026-82779, CVE-2026-82780, CVE-2020-7746)
  • CPS-TM341MB-ADSC1-931 versions prior to 2.19 (CVE-2026-82779, CVE-2026-82780, CVE-2020-7746)
  • CPSL-08P1EN versions prior to 2.3.10 (CVE-2026-82787, CVE-2026-82788, CVE-2020-7746)
  • M2M Gateway Integrated Type CPS-MG341* versions prior to 4.1.0 (CVE-2026-82773, CVE-2026-82774, CVE-2026-82775, CVE-2020-7746)
  • M2M Gateway Configurable type CPS-MGS341* versions prior to 4.1.0 (CVE-2026-82773, CVE-2026-82774, CVE-2026-82775, CVE-2020-7746)
  • M2M Controller Integrated Type CPS-MC341 versions prior to 4.1.0 (CVE-2026-82773, CVE-2026-82774, CVE-2026-82775, CVE-2020-7746)
  • M2M Controller Configurable type CPS-MCS341* versions prior to 4.1.0 (CVE-2026-82773, CVE-2026-82774, CVE-2026-82775, CVE-2020-7746)
  • Integrated Type CPS-PC341[][]-*-9201 versions prior to 3.0.0 (CVE-2026-82776, CVE-2026-82777, CVE-2026-82778, CVE-2020-7746)
  • Configurable type CPS-PCS341[][]-DS1-1201 versions prior to 3.0.0 (CVE-2026-82776, CVE-2026-82777, CVE-2026-82778, CVE-2020-7746)
  • Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041 versions prior to 1.61 (CVE-2026-82781, CVE-2026-82782, CVE-2026-82764, CVE-2026-82783)
  • Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 versions prior to 1.02 (CVE-2026-82781, CVE-2026-82782, CVE-2026-82764, CVE-2026-82783)
  • Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* versions prior to 1.82 (CVE-2026-82781, CVE-2026-82782, CVE-2026-82764, CVE-2026-82783, CVE-2026-82784, CVE-2026-82785, CVE-2026-82786)

Impact

  • An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-82773, CVE-2026-82776, CVE-2026-82781, CVE-2026-82788).
  • An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-82774, CVE-2026-82777, CVE-2026-82779).
  • Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication (CVE-2026-82775, CVE-2026-82778).
  • A denial-of-service (DoS) condition may be caused by an attacker (CVE-2020-7746).
  • If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product (CVE-2026-82780).
  • Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition (CVE-2026-82782, CVE-2026-82785).
  • If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed (CVE-2026-82764)
  • An attacker with physical access to the product may obtain credentials (CVE-2026-82783).
  • An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output (CVE-2026-82784).
  • Sensitive information may be restored from a backup file (CVE-2026-82786).
  • An affected product may be operated by a remote attacker without authentication (CVE-2026-82787).
  • Arbitrary code may be executed by an attacker who can log in to the product (CVE-2026-82789).
Solution

[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
Vendor Information

Contec
CWE (What is CWE?)

  1. Stack-based Buffer Overflow(CWE-121) [Other]
  2. Dependency on Vulnerable Third-Party Component(CWE-1395) [Other]
  3. Unprotected Storage of Credentials(CWE-256) [Other]
  4. Missing Authentication for Critical Function(CWE-306) [Other]
  5. Cross-Site Request Forgery(CWE-352) [Other]
  6. Unrestricted Upload of File with Dangerous Type(CWE-434) [Other]
  7. Insufficiently Protected Credentials(CWE-522) [Other]
  8. Exposure of Information Through Directory Listing(CWE-548) [Other]
  9. OS Command Injection(CWE-78) [Other]
  10. Out-of-bounds Write(CWE-787) [Other]
  11. Cross-site Scripting(CWE-79) [Other]
  12. Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')(CWE-95) [Other]
CVE (What is CVE?)

  1. CVE-2020-7746
  2. CVE-2026-82764
  3. CVE-2026-82773
  4. CVE-2026-82774
  5. CVE-2026-82775
  6. CVE-2026-82776
  7. CVE-2026-82777
  8. CVE-2026-82778
  9. CVE-2026-82779
  10. CVE-2026-82780
  11. CVE-2026-82781
  12. CVE-2026-82782
  13. CVE-2026-82783
  14. CVE-2026-82784
  15. CVE-2026-82785
  16. CVE-2026-82786
  17. CVE-2026-82787
  18. CVE-2026-82788
  19. CVE-2026-82789
References

  1. JVN : JVNVU#96551518
Revision History

  • [2026/09/14]
      Web page was published