CVE-2026-82789
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Contec | CONPROSYS HMI System(CHS) | 0 < 3.8.0 | affected |
Weaknesses
- CWE-95: Improper neutralization of directives in dynamically evaluated code ('Eval Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf
- https://jvn.jp/en/vu/JVNVU96551518/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.