Executive brief
Contec's CONPROSYS nano Remote I/O Coupler Unit is an industrial I/O device used to manage input/output signals in manufacturing and automation systems. A weakness in how credentials are stored allows an attacker with network access and some complexity to recover sensitive authentication information from backup files, potentially gaining unauthorized access to critical industrial systems and their data.
Technical details
This vulnerability (CVE-2026-82786) is classified as insufficiently protected credentials (CWE-522) affecting the Remote I/O Coupler Unit Server Type CPSN-MCB271-* in versions prior to 1.82. The root cause is weak credential storage mechanisms that allow sensitive authentication data to be restored from backup files. An attacker must have network access and moderate complexity conditions to exploit this, but does not require prior authentication. Successful exploitation allows an attacker to retrieve stored credentials, potentially enabling lateral movement within an industrial control network or unauthorized system access. A patch is available in version 1.82 and later.
Affected products
- Contec CONPROSYS nano Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* prior to 1.82
Timeline
- 2026-09-10: advisory
- 2026-09-14: disclosed