Junglewise Threat Intelligence

CVE-2026-82786: Contec CONPROSYS nano Remote I/O Coupler insufficiently protected credentials

CVE-2026-82786 · Severity: medium · CVSS 6.3 · Published 2026-09-14

Technologies: Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271. Vendors: Contec.

Executive brief

Contec's CONPROSYS nano Remote I/O Coupler Unit is an industrial I/O device used to manage input/output signals in manufacturing and automation systems. A weakness in how credentials are stored allows an attacker with network access and some complexity to recover sensitive authentication information from backup files, potentially gaining unauthorized access to critical industrial systems and their data.

Technical details

This vulnerability (CVE-2026-82786) is classified as insufficiently protected credentials (CWE-522) affecting the Remote I/O Coupler Unit Server Type CPSN-MCB271-* in versions prior to 1.82. The root cause is weak credential storage mechanisms that allow sensitive authentication data to be restored from backup files. An attacker must have network access and moderate complexity conditions to exploit this, but does not require prior authentication. Successful exploitation allows an attacker to retrieve stored credentials, potentially enabling lateral movement within an industrial control network or unauthorized system access. A patch is available in version 1.82 and later.

Affected products

  • Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* prior to 1.82

Timeline

  • 2026-09-10: advisory
  • 2026-09-14: disclosed

References

Related threats