Executive brief
Contec's CONPROSYS nano Remote I/O Coupler Unit (Server Type) is an industrial control device used to manage input/output operations in factory and infrastructure automation systems. A stack-based buffer overflow vulnerability allows a remote attacker to send a specially crafted request that crashes the device, causing a denial-of-service (DoS) and disrupting critical industrial operations.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* when processing specially crafted network requests. The vulnerability is triggered by a remote attacker sending malformed input without requiring authentication. Exploitation of this flaw causes a denial-of-service condition that interrupts the device's operation. The vulnerability affects versions prior to 1.82, and a patch is available in version 1.82 and later.
Affected products
- Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271 prior to 1.82
Timeline
- 2026-09-14: disclosed: CVE-2026-82785 published on NVD