PT-2026-91091 · Contec · Cpsl-08P1En

CVE-2026-82787

·

Published

2026-09-14

·

Updated

2026-09-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contec CPSL-08P1EN versions prior to 2.3.1.0
Description A missing authentication for critical function issue exists in the web settings function of the device. A remote attacker with network access to the management service can operate the affected product without authentication. Successful exploitation may lead to data theft, tampering, and the execution of malicious programs. This occurs because the server-side identity enforcement fails to properly validate authentication before allowing sensitive operations on the settings screen.
Recommendations Update CPSL-08P1EN to firmware 2.3.1.0 or later. Disconnect the product from network lines, place a firewall upstream to allow only trusted communications, and restrict access to a trusted closed network.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82787

Affected Products

Cpsl-08P1En