Junglewise Threat Intelligence

CVE-2026-82774: Contec CONPROSYS M2M Gateway OS command injection

CVE-2026-82774 · Severity: high · CVSS 8.8 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec CONPROSYS M2M Gateway is a networked device that bridges industrial equipment communications. A vulnerability allows authenticated users to execute arbitrary operating system commands on the gateway, potentially compromising the integrity of industrial systems and the data they manage. This could enable an insider threat or an attacker who has obtained login credentials to take complete control of the device and connected systems.

Technical details

This vulnerability is an OS command injection (CWE-78) that exists in CONPROSYS M2M Gateway Series (both Integrated Type CPS-MG341* and Configurable type CPS-MGS341*) in versions prior to 4.1.0. The attack vector is network-based and requires valid authentication credentials. An attacker with authenticated access can inject malicious OS commands through improperly sanitized input fields, leading to arbitrary command execution with the privileges of the gateway process. Contec has released patched versions 4.1.0 and later that address this vulnerability.

Affected products

  • Contec CONPROSYS M2M Gateway Integrated Type CPS-MG341* prior to 4.1.0
  • Contec CONPROSYS M2M Gateway Configurable Type CPS-MGS341* prior to 4.1.0

Timeline

  • 2026-09-10: disclosed: Vulnerability disclosed by Contec via JVN advisory JVNVU#96551518
  • 2026-09-14: advisory: CVE-2026-82774 published to NVD

References