Junglewise Threat Intelligence

CVE-2026-82791: Contec CAN 2.0B Communication Wireless LAN/USB Converter OS command injection

CVE-2026-82791 · Severity: high · CVSS 8.8 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec's CAN 2.0B Communication Wireless LAN/USB Converter Unit is an industrial networking device used to connect legacy CAN bus systems to modern networks. An authenticated attacker with login access can exploit a command injection vulnerability to execute arbitrary operating system commands with device-level privileges, potentially compromising industrial control systems and the networks they support.

Technical details

An OS command injection vulnerability (CWE-78) exists in the device's command processing logic that fails to properly neutralize special shell characters. The vulnerability requires valid authentication credentials, but no user interaction is needed once an attacker is logged in. An authenticated attacker can inject shell metacharacters into input fields to break out of intended command context and execute arbitrary OS commands with the device's privileges. This could lead to complete device compromise, unauthorized network access, or manipulation of industrial control data. Firmware updates to version 2.20 or later for affected models (CAN-2-WF and CAN-2-USB) address this issue.

Affected products

  • Contec CAN-2-WF prior to 2.20
  • Contec CAN-2-USB prior to 2.20

Timeline

  • 2026-09-14: disclosed

References

Related threats