VulnSea

Contec Co., Ltd. has 32 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 32. The median CVSS is 6.1 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (12) and CWE-78 (6). Most affected products: Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* (6), FXA5000 (4), CAN-2-WF (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
32 prev 0

Products

  • Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* 6
  • FXA5000 4
  • CAN-2-WF 3
  • Integrated Type CPS-PC341[][]-*-9201 3
  • M2M Gateway Integrated Type CPS-MG341* 3
  • SGA1000 3
32
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Contec Co., Ltd. vulnerabilities

CVEs affecting Contec Co., Ltd., newest first. Open any entry for full detail, references, and exploit status.

32 CVEsRSS

CVE-2026-82796Medium· 5.4
1w ago

SolarView Compact contains a cross-site scripting vulnerability in Image Management

SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.14%via NVD
CVE-2026-82788Medium· 6.1
1w ago

Cross-site scripting vulnerability exists in CPSL-08P1EN

Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · CPSL-08P1ENEPSS 0.15%via NVD
CVE-2026-82787Critical· 9.8
1w ago

Missing authentication for critical function vulnerability exists in CPSL-08P1EN

Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.

MidnightContec Co., Ltd. · CPSL-08P1ENEPSS 0.36%via NVD
CVE-2026-82786Medium· 6.3
1w ago

Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.19%via NVD
CVE-2026-82785Medium· 4.3
1w ago

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.30%via NVD
CVE-2026-82784Medium· 6.5
1w ago

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values an…

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.20%via NVD
CVE-2026-82783Medium· 4.2
1w ago

Plaintext storage of a password issue exists in CONPROSYS nano Series

Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.13%via NVD
CVE-2026-82782Medium· 4.3
1w ago

Out-of-bounds write vulnerability exists in CONPROSYS nano Series

Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.27%via NVD
CVE-2026-82781Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in CONPROSYS nano Series

Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.14%via NVD
CVE-2026-82778Medium· 4.3
1w ago

An exposure of information through directory listing issue exists in CONPROSYS PAC Series

An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

SunlitContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 0.26%via NVD
CVE-2026-82763Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · FXA5000EPSS 0.14%via NVD
CVE-2026-82777High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to…

TwilightContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 1.2%via NVD
CVE-2026-82776Medium· 6.1
1w ago

Cross-site scripting vulnerability exists in CONPROSYS PAC Series

Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 0.19%via NVD
CVE-2026-82775Medium· 4.3
1w ago

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the dir…

SunlitContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 0.32%via NVD
CVE-2026-82774High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may …

TwilightContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 1.2%via NVD
CVE-2026-82773Medium· 6.1
1w ago

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 0.19%via NVD
CVE-2026-82772High· 8.8
1w ago

Buffer overflow vulnerability exists in Contec EC1000 series

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

TwilightContec Co., Ltd. · ECE1000EPSS 0.46%via NVD
CVE-2026-82771Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in Contec EC1000 series

Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · ECE1000EPSS 0.17%via NVD
CVE-2026-82770High· 8.8
1w ago

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

TwilightContec Co., Ltd. · RP-WAH-SR1EPSS 0.46%via NVD
CVE-2026-82769Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · RP-WAH-SR1EPSS 0.17%via NVD
CVE-2026-82767Medium· 5.2
1w ago

Cross-site scripting vulnerability exists in SGA1000

Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · SGA1000EPSS 0.16%via NVD
CVE-2026-82766High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

TwilightContec Co., Ltd. · SGA1000EPSS 1.2%via NVD
CVE-2026-82764Medium· 4.3
1w ago

Cross-site request forgery vulnerability exists in multiple Contec products

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.

SunlitContec Co., Ltd. · FXA5000EPSS 0.15%via NVD
CVE-2026-82762High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be execute…

TwilightContec Co., Ltd. · FXA5000EPSS 1.2%via NVD
CVE-2026-82794High· 8.8
1w ago

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

TwilightContec Co., Ltd. · SV-CPT-MC310EPSS 1.0%via NVD
CVE-2026-82793High· 7.2
1w ago

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed o…

TwilightContec Co., Ltd. · CAN-2-WFEPSS 0.35%via NVD
CVE-2026-82792Medium· 5.2
1w ago

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · CAN-2-WFEPSS 0.15%via NVD
CVE-2026-82791High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may b…

TwilightContec Co., Ltd. · CAN-2-WFEPSS 1.0%via NVD
CVE-2026-82790Medium· 5.4
1w ago

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

SunlitContec Co., Ltd. · PC-HELPER Wireless I/O DIO-0404RY-LWFEPSS 0.14%via NVD
CVE-2026-82795Medium· 5.4
1w ago

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.14%via NVD
Contec Co., Ltd. vulnerabilities (CVEs) · VulnSea