Executive brief
Contec CONPROSYS nano Remote I/O Coupler Unit is an industrial control device used to read and manage electrical I/O signals in factory automation systems. An unauthenticated attacker can call REST API functions to remotely read sensor values or control equipment outputs without any login credentials, potentially disrupting manufacturing operations or stealing sensor data.
Technical details
This is a missing authentication vulnerability (CWE-306) in the REST API of the CONPROSYS nano Remote I/O Coupler Unit (Server Type). The vulnerability allows an unauthenticated network attacker to invoke API endpoints that retrieve I/O values or control output states without providing credentials. The attack vector is network-based with no authentication required and no user interaction needed. An attacker can exploit this to both read sensitive sensor data and manipulate industrial control outputs remotely. The fix is available in version 1.82 or later for the CPSN-MCB271-* product line.
Affected products
- Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271 prior to 1.82
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory