CVE-2026-82774: Command Injection
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to log in to an affected CONPROSYS M2M Gateway Series or CONPROSYS M2M Controller Series product. The provided information does not indicate that unauthenticated attackers can exploit it.
What could successful exploitation allow?
A successful attacker can execute arbitrary OS commands on the affected product. The listed impact includes high confidentiality, integrity, and availability impact.
Is user interaction required for exploitation?
No user interaction is required according to the supplied vector. Exploitation is rated as network-accessible with low attack complexity, but it requires low privileges.