Sceawere

Vulnerability Detail

CVE-2026-82793UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unrestricted File Upload RCE Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
CAN-2-WF
Attack Type
Unrestricted upload of file with dangerous type
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-14T07:17:21.480Z",
  "pubdate": "2026-09-14T07:17:21.480Z",
  "executiveSummary": "A critical vulnerability exists in the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit involving an unrestricted file upload mechanism. This flaw allows a remote authenticated attacker to upload arbitrary files with dangerous extensions or content types to the system. By bypassing intended file validation controls, an attacker can achieve remote code execution (RCE) on the underlying operating system or firmware environment. The vulnerability poses a significant security risk, as successful exploitation grants the attacker the ability to execute unauthorized commands with the privileges of the web service or application process. This compromise can lead to complete system takeover, data exfiltration, or the establishment of persistent backdoors within the network infrastructure. Exploitation requires the attacker to possess authenticated access to the management interface, though no further complex prerequisites are needed to weaponize the upload function for arbitrary code execution.",
  "technicalDetails": "The core vulnerability is identified as an Unrestricted Upload of File with Dangerous Type, stemming from the application's failure to enforce stringent validation policies on user-supplied file uploads. Within the Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit, the file upload functionality lacks a robust mechanism to verify the integrity, extension, or MIME type of incoming data before it is persisted to the local file system. This weakness effectively allows an attacker to bypass file-based access control lists (ACLs) and security filters.\nThe exploitation process typically follows a structured attack flow. First, an authenticated attacker interacts with the product's administrative or configuration interface to access the file upload module. By crafting a malicious payload, such as a script file (e.g., PHP, ASP, or binary executables configured to run in the target environment), the attacker bypasses surface-level checks if they exist, often through simple renaming, double extensions, or manipulation of the Content-Type header in the HTTP request. Once the payload is successfully uploaded to an accessible directory, the attacker triggers its execution by requesting the file directly via the web server.\nUpon successful execution, the injected code runs within the security context of the web application service. Because the device is intended for communication management, the application process likely maintains high-level privileges, allowing the attacker to interact with the device's operating system, modify configuration parameters, or pivot deeper into the connected industrial or network environment. Post-exploitation impact includes, but is not limited to, unauthorized access to sensitive CAN bus traffic, modification of operational parameters, and the potential for long-term persistence through the deployment of rootkits or unauthorized service modification. The lack of secondary file execution prevention measures—such as moving uploads to a non-executable directory or enforcing strict renaming policies—exacerbates the severity of this vulnerability, enabling the attacker to transition from an authenticated user to a full system administrator."
}
CVE-2026-82793: Unrestricted File Upload RCE Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere