Executive brief
Contec CONPROSYS TM Series is an industrial automation controller used to manage factory equipment and processes. A vulnerability allows authenticated users to execute arbitrary operating system commands on the device, potentially disrupting critical manufacturing operations or enabling further compromise of the industrial network.
Technical details
An OS command injection vulnerability (CWE-78) exists in CONPROSYS TM Series due to improper neutralization of special elements in user input passed to OS commands. The vulnerability requires authentication to exploit; an attacker with valid login credentials can supply specially crafted input through the product's interface that will be executed as arbitrary OS commands. This allows complete compromise of the affected device including reading/modifying files, executing malicious code, and pivoting to other systems on the network. Patches are available in firmware version 2.19 for affected TM Series models.
Affected products
- Contec CONPROSYS TM Series before 2.19
Timeline
- 2026-09-14: disclosed: CVE-2026-82779 published
- 2026-09-14: patched: Fixed in firmware version 2.19