Executive brief
Klemsan KIO (Klemsan Internet Objects) is an industrial control system component used in electrical equipment. A code injection vulnerability allows attackers to execute arbitrary code through improper input validation, potentially compromising system integrity and enabling unauthorized control or data theft.
Technical details
The vulnerability is a code injection flaw (CWE-94: Improper Control of Generation of Code) in Klemsan KIO before version 1.9. The root cause stems from insufficient input validation and sanitization when processing user-supplied data that influences code generation or execution. Attack vectors appear to include network-accessible interfaces, and a CVSS score of 9.8 suggests minimal authentication barriers and high attack complexity. Successful exploitation allows an attacker to inject and execute arbitrary code on the affected system, potentially leading to complete system compromise.
Affected products
- Klemsan Electrical Electronics Inc. KIO before v1.9
Timeline
- 2026-09-01: disclosed