Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-82787: cpsl-08p1en can be controlled remotely without login

CVE-2026-82787 · published 15 days ago
Summary

The CPSL-08P1EN device from Contec allows a critical function to be accessed without any authentication. This means a remote attacker could operate the device as if they were an authorized user. Apply the vendor's security update or restrict network access to the device until a fix is installed.

What to do
  • Update contec co., ltd. cpsl-08p1en to version 2.3.10 or later.
Affected software
VendorProductAffected versions
contec co., ltd. cpsl-08p1en < 2.3.10
Original advisory text
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
Severity
8.7 High
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published14 Sep 2026
Updated27 Sep 2026
First seen14 Sep 2026
Sources
CVE-2026-82787 · MITRE
Track software like this
Free during beta