Junglewise Threat Intelligence

CVE-2026-82782: Contec CONPROSYS nano out-of-bounds write in remote I/O coupler

CVE-2026-82782 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec CONPROSYS nano is a family of industrial remote I/O coupler and controller devices used in manufacturing and process automation systems. An out-of-bounds write vulnerability in certain nano Series devices can be triggered by sending a specially crafted network request, allowing a remote attacker to cause a denial-of-service condition that disrupts production systems.

Technical details

This is a CWE-787 out-of-bounds write vulnerability affecting CONPROSYS nano Series devices. The vulnerability exists in the remote I/O coupler unit (server type) CPSN-MCB271-* and related models, triggered by receiving a specially crafted request over the network from an unauthenticated remote attacker. The flaw results in a denial-of-service condition, specifically limited availability impact. Affected versions prior to 1.82 (CPSN-MCB271-*), 1.02 (CPSN-EOB471EI-[]1), and 1.61 (CPSN-PCB271-S1-041) are vulnerable; patched versions addressing this issue are available.

Affected products

  • Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* versions prior to 1.82
  • Contec CONPROSYS nano Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 versions prior to 1.02
  • Contec CONPROSYS nano Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041 versions prior to 1.61

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References

Related threats