Junglewise Threat Intelligence

CVE-2026-82772: Contec EC1000 buffer overflow in web service

CVE-2026-82772 · Severity: high · CVSS 8.8 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec EC1000 series industrial networking devices contain a buffer overflow vulnerability in their web service component. A remote attacker can send a specially crafted request to trigger arbitrary code execution, potentially gaining full control of the device and compromising network operations.

Technical details

A buffer overflow vulnerability (CWE-120) exists in the EC1000 series web service that allows remote code execution without requiring prior authentication. The vulnerability is triggered by sending a specially crafted request to the web service interface. An unauthenticated remote attacker can exploit this to execute arbitrary programs with the privileges of the vulnerable service. The affected versions are ECE1000, ECE1020, and ECS1020 prior to version 1.02; firmware updates are available from Contec.

Affected products

  • Contec ECE1000 prior to 1.02
  • Contec ECE1020 prior to 1.02
  • Contec ECS1020 prior to 1.02

Timeline

  • 2026-09-14: disclosed

References