CVE-2026-82762: Command Injection
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to log in to an affected Contec FX5000, FX4000, or FX3000 series product. The provided information does not indicate that unauthenticated attackers can exploit it.
What access could an attacker gain after exploitation?
A logged-in attacker may execute arbitrary OS commands on the affected product. The listed impact includes high confidentiality, integrity, and availability impact.
Is the default configuration affected?
The available information does not state whether the vulnerable functionality is enabled or reachable in the default configuration.
How can I determine whether I am affected?
Identify whether your environment uses a Contec FX5000, FX4000, or FX3000 series product. The provided data does not include affected or fixed version numbers, so it cannot determine exposure more precisely.