Junglewise Threat Intelligence

CVE-2026-82783: Contec CONPROSYS nano plaintext password storage

CVE-2026-82783 · Severity: medium · CVSS 4.2 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec CONPROSYS nano Series is a remote I/O coupler unit used in industrial control systems to manage input/output operations across networks. A vulnerability in the product stores authentication credentials in plaintext, allowing an attacker with physical access to the device to extract login credentials and gain unauthorized access to control the system or access sensitive data.

Technical details

This vulnerability (CWE-256) involves plaintext storage of credentials in the CONPROSYS nano Series remote I/O coupler units. An attacker with physical access to the affected device can retrieve stored passwords without authentication or special tools. The vulnerability affects multiple nano Series models including Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*, Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-*1, and Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041. Patches are available: versions prior to 1.82 (MCB271), 1.02 (EOB471EI), and 1.61 (PCB271) are affected; updated versions address the plaintext credential storage issue.

Affected products

  • Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* prior to 1.82
  • Contec CONPROSYS nano Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-*1 prior to 1.02
  • Contec CONPROSYS nano Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041 prior to 1.61

Timeline

  • 2026-09-14: disclosed: Vulnerability disclosed by Contec and published in JVNVU#96551518

References

Related threats