Executive brief
Contec SGA1000 is an industrial networking device used to provide secure gateway and automation functions in factory and IoT environments. An authenticated attacker can inject arbitrary operating system commands, potentially allowing them to take complete control of the device, manipulate critical processes, or disrupt operations.
Technical details
This is an OS command injection vulnerability (CWE-78) in the SGA1000 industrial gateway that permits an attacker with valid login credentials to execute arbitrary system commands. The vulnerability requires prior authentication but does not require user interaction; it is reachable over the network. Successful exploitation grants an attacker the ability to execute arbitrary commands with the privileges of the affected application, potentially leading to full system compromise, data exfiltration, and operational disruption. Firmware updates are available; affected versions prior to 1.02 should be patched immediately.
Affected products
- Contec SGA1000 prior to 1.02
Timeline
- 2026-09-14: disclosed
- 2026-09-10: advisory: JVNVU#99009004 published