CVE-2026-82791: Command Injection
Published Sep 14, 2026
·Updated
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Affected Software
1 affected component
Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit
Event History
Sep 14, 2026
CVE Published
via MITRE·06:45 AM
Data Sourced
via MITRE·06:45 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be able to log in to the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. The vulnerability is reachable over the network and does not require user interaction.
2
What could a successful attack allow?
A successful exploit can allow the authenticated attacker to execute arbitrary OS commands. This can affect confidentiality, integrity, and availability.