Executive brief
Contec's FLEXLAN series are industrial networking products (routers/gateways) used to connect and manage remote sites. An authenticated attacker who logs into the device's management interface can inject arbitrary operating system commands, potentially taking full control of the device and compromising any systems it protects or connects to.
Technical details
This is an OS command injection vulnerability (CWE-78) affecting multiple FLEXLAN product lines. The vulnerability requires authentication to the device's web interface or management system, meaning an attacker must have valid login credentials or bypass authentication. Once authenticated, the attacker can inject specially crafted input into a vulnerable parameter that is passed unsanitized to an OS command execution function, allowing arbitrary command execution with the privileges of the application. The CVSS 8.8 score reflects high impact (confidentiality, integrity, and availability) with low attack complexity but requiring prior authentication. Patches are available from Contec; users should update firmware to FX5000 series v1.12.00 or later, FX4000 series v1.14.00 or later, and FX3000 series v1.20.00 or later.
Affected products
- Contec FXA5000 versions prior to 1.12.00
- Contec FXA5020 versions prior to 1.12.00
- Contec FXE5000 versions prior to 1.12.00
- Contec FXS5000 versions prior to 1.12.00
- Contec FXS5021 versions prior to 1.12.00
- Contec FXE4000 versions prior to 1.14.00
- Contec FXE4000-WP versions prior to 1.14.00
- Contec FXS4000 versions prior to 1.14.00
- Contec FXS4020 versions prior to 1.14.00
- Contec FXA3000 versions prior to 1.20.00
- Contec FXA3020 versions prior to 1.20.00
- Contec FXA3200 versions prior to 1.20.00
- Contec FXE3000 versions prior to 1.20.00
- Contec FXE3000-WP versions prior to 1.20.00
Timeline
- 2026-09-14: disclosed