PT-2026-91091 · Contec · Cpsl-08P1En
CVE-2026-82787
·
Published
2026-09-14
·
Updated
2026-09-20
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contec CPSL-08P1EN versions prior to 2.3.1.0
Description
A missing authentication for critical function issue exists in the web settings function of the device. A remote attacker with network access to the management service can operate the affected product without authentication. Successful exploitation may lead to data theft, tampering, and the execution of malicious programs. This occurs because the server-side identity enforcement fails to properly validate authentication before allowing sensitive operations on the settings screen.
Recommendations
Update CPSL-08P1EN to firmware 2.3.1.0 or later.
Disconnect the product from network lines, place a firewall upstream to allow only trusted communications, and restrict access to a trusted closed network.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpsl-08P1En