---
id: CVE-2026-82762
title: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000
  series
summary: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000
  series. If this vulnerability is exploited, an arbitrary OS command may be
  execute…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: 'Contec Co., Ltd.'
product: FXA5000
affected:
  - FXA5000 < 1.12.00
  - FXA5020 < 1.12.00
  - 'FXA5020-[][] < 1.12.00'
  - FXE5000 < 1.12.00
  - 'FXE5000-[][] < 1.12.00'
  - 'FXS5000-[][] < 1.12.00'
  - FXS5021 < 1.12.00
  - FXE4000 < 1.14.00
  - FXE4000-WP < 1.14.00
  - FXS4000 < 1.14.00
  - FXS4020 < 1.14.00
  - FXA3000 < 1.20.00
  - 'FXA3000-[][] < 1.20.00'
  - FXA3020 < 1.20.00
  - 'FXA3020-[][] < 1.20.00'
  - FXA3200 < 1.20.00
  - FXE3000 < 1.20.00
  - 'FXE3000-[][] < 1.20.00'
  - FXE3000-WP < 1.20.00
  - 'FXS300[]-CN < 1.20.00'
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82762'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU99009004/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_fl_26091000_en.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.01868
epssPercentile: 0.78427
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T11:10:36.250352Z'
ingestedAt: '2026-09-14T15:23:07.461Z'
---

## Overview

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
