Executive brief
CONPROSYS TM Series is an industrial controller product used in manufacturing and automation environments. A vulnerability allows authenticated users to upload specially crafted files that lead to arbitrary command execution on the device, potentially compromising the entire industrial system and halting production.
Technical details
The vulnerability is an unrestricted upload of file with dangerous type (CWE-434) in the CONPROSYS TM Series. An authenticated attacker can upload a specially crafted file that bypasses file type validation, resulting in arbitrary command execution on the affected device. The attack requires authentication and network access to the product's upload interface. Successful exploitation allows an attacker to execute arbitrary OS commands with the privileges of the affected service, potentially leading to complete system compromise. Patches are available for affected versions prior to 2.19.
Affected products
- Contec CONPROSYS TM Series prior to 2.19
Timeline
- 2026-09-14: disclosed