Executive brief
Contec RP-WAH-SR Series is a network appliance used in industrial automation environments. A remote attacker can send a specially crafted request to the web service to execute arbitrary code without authentication, potentially compromising the device and disrupting critical infrastructure operations.
Technical details
A buffer overflow vulnerability (CWE-120) exists in the RP-WAH-SR Series web service component. The vulnerability allows a remote attacker to send a specially crafted request that causes a buffer overflow, leading to arbitrary program execution. The attack is network-accessible and requires low complexity, though the CVSS vector indicates login credentials may be required (PR:L suggests privilege level requirement). Patches are available; affected firmware versions include RP-WAH-SR1 and RP-WAH-SR2 versions prior to 1.03, and RP-WAH-SR12 and RP-WAH-SR22 versions prior to 1.02.
Affected products
- Contec RP-WAH-SR1 prior to 1.03
- Contec RP-WAH-SR2 prior to 1.03
- Contec RP-WAH-SR12 prior to 1.02
- Contec RP-WAH-SR22 prior to 1.02
Timeline
- 2026-09-14: disclosed: Vulnerability publicly disclosed via NVD and JVNVU#99009004