---
id: CVE-2026-82774
title: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M
  Controller Series
summary: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M
  Controller Series. If this vulnerability is exploited, an arbitrary OS command
  may …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: 'Contec Co., Ltd.'
product: M2M Gateway Integrated Type CPS-MG341*
affected:
  - m2m_gateway_integrated_type_cps-mg341 < 4.1.0
  - m2m_gateway_configurable_type_cps-mgs341 < 4.1.0
  - m2m_controller_integrated_type_cps-mc341 < 4.1.0
  - m2m_controller_configurable_type_cps-mcs341 < 4.1.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82774'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU96551518/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.01868
epssPercentile: 0.78426
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T11:08:21.160781Z'
ingestedAt: '2026-09-14T15:23:07.461Z'
---

## Overview

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
