Sceawere
Vulnerability Detail
CVE-2026-82780UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CONPROSYS TM Series Unrestricted Upload
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Contec Co., Ltd
- Product
- CPS-TM341G5MB-ADSC1-931
- Attack Type
- Unrestricted upload of file with dangerous type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-14T07:17:19.663Z",
"pubdate": "2026-09-14T07:17:19.663Z",
"executiveSummary": "The CONPROSYS TM Series is susceptible to an Unrestricted Upload of File with Dangerous Type vulnerability, classified as a critical security flaw.\nThis vulnerability enables a remote, authenticated attacker to bypass file validation mechanisms and upload malicious payloads to the target device.\nUpon successful upload, the attacker can achieve arbitrary command execution, leading to full system compromise, potential data exfiltration, or complete loss of control over the industrial control system.\nThe vulnerability is primarily driven by improper server-side validation of file metadata or content types during the upload process.\nThe risk is elevated due to the nature of industrial hardware, where unauthorized code execution can lead to operational disruption, safety hazards, or permanent damage to physical processes.\nExploitation requires the attacker to have established authenticated access to the management interface of the target product.\nOrganizations relying on the CONPROSYS TM Series must prioritize access control and network segmentation to mitigate the potential for unauthorized exploitation of this upload flaw.",
"technicalDetails": "The root cause of the vulnerability lies in the insufficient enforcement of file type and content validation policies within the CONPROSYS TM Series file upload functionality.\nWhen a file is uploaded via the administrative or configuration interface, the system fails to adequately sanitize or verify the file extension, MIME type, or the executable nature of the file content before storing it in the file system.\nAn authenticated attacker can leverage this flaw by crafting a malicious file—such as a script, binary, or configuration override file—designed to be interpreted or executed by the underlying operating system or an application-level script engine.\nThe attack flow typically follows a structured sequence: First, the attacker establishes a valid session with the device using legitimate credentials. Second, the attacker locates the vulnerable file upload endpoint. Third, the attacker initiates a multipart/form-data request to upload the malicious payload, potentially masking it with a permitted file extension if blocklists are used instead of allowlists.\nOnce the file is successfully uploaded to a directory accessible by the web server or a background task process, the attacker triggers the execution of the payload. This is often achieved by navigating to the file path via the web browser or by forcing the application to reference the uploaded file through existing system functionality.\nThe impact of arbitrary command execution at this level is severe. The payload runs with the privileges of the service account responsible for the file management, which in many embedded industrial products is a high-privilege account (e.g., root or a system-level service user).\nPost-exploitation activities include the deployment of persistent backdoors, modification of device configurations, interception of operational traffic, or the use of the device as a pivot point within the industrial control network to target other critical assets.\nThe lack of integrity verification for uploaded files allows the attacker to replace legitimate system files, potentially leading to a permanent compromise that survives reboots unless factory recovery procedures are strictly enforced."
}