Contec Co., Ltd.
Products
41- 19 CVEs
- 15 CVEs
- 15 CVEs
- 14 CVEs
- 7 CVEs
- 6 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- View all 41 products →
Recent CVEs
51| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29303 | Cri | 0.87 | 9.8 | 0.98 | KEV | May 12, 2022 | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | |
| CVE-2023-23333 | Cri | 0.75 | 9.8 | 0.99 | Feb 6, 2023 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | ||
| CVE-2022-44456 | Cri | 0.69 | 9.8 | 0.70 | Dec 19, 2022 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. | ||
| CVE-2022-40881 | Cri | 0.66 | 9.8 | 0.29 | Nov 17, 2022 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | ||
| CVE-2024-12248 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2025 | Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution. | ||
| CVE-2023-46509 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2023 | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. | ||
| CVE-2023-29919 | Cri | 0.64 | 9.1 | 0.60 | May 23, 2023 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | ||
| CVE-2022-44354 | Cri | 0.64 | 9.8 | 0.02 | Nov 29, 2022 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. | ||
| CVE-2022-31374 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2022 | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file. | ||
| CVE-2021-20658 | Cri | 0.64 | 9.8 | 0.04 | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors. | ||
| CVE-2018-9162 | Cri | 0.64 | 9.8 | 0.02 | Mar 31, 2018 | Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors. | ||
| CVE-2023-28657 | Hig | 0.57 | 8.8 | 0.01 | Jun 1, 2023 | Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed may gain an administrative privilege. As a result, information regarding the product may be obtained and/or altered by the… | ||
| CVE-2023-27521 | Hig | 0.57 | 8.8 | 0.02 | May 23, 2023 | OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command. | ||
| CVE-2023-27518 | Hig | 0.57 | 8.8 | 0.02 | May 23, 2023 | Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute arbitrary code. | ||
| CVE-2023-27514 | Hig | 0.57 | 8.8 | 0.02 | May 23, 2023 | OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbitrary OS command. | ||
| CVE-2023-27917 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2023 | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the… | ||
| CVE-2022-36159 | Hig | 0.57 | 8.8 | 0.01 | Sep 26, 2022 | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN… | ||
| CVE-2022-35239 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2022 | The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a… | ||
| CVE-2021-20659 | Hig | 0.57 | 8.8 | 0.02 | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code. | ||
| CVE-2022-29298 | Hig | 0.55 | 7.5 | 0.47 | May 12, 2022 | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. |
- risk 0.87cvss 9.8epss 0.98
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
- risk 0.75cvss 9.8epss 0.99
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
- risk 0.69cvss 9.8epss 0.70
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
- risk 0.66cvss 9.8epss 0.29
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
- risk 0.64cvss 9.8epss 0.01
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
- risk 0.64cvss 9.8epss 0.01
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
- risk 0.64cvss 9.1epss 0.60
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
- risk 0.64cvss 9.8epss 0.02
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
- risk 0.64cvss 9.8epss 0.04
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
- risk 0.64cvss 9.8epss 0.02
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.
- risk 0.57cvss 8.8epss 0.01
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC where the affected product is installed may gain an administrative privilege. As a result, information regarding the product may be obtained and/or altered by the…
- risk 0.57cvss 8.8epss 0.02
OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command.
- risk 0.57cvss 8.8epss 0.02
Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute arbitrary code.
- risk 0.57cvss 8.8epss 0.02
OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbitrary OS command.
- risk 0.57cvss 8.8epss 0.02
OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the…
- risk 0.57cvss 8.8epss 0.01
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN…
- risk 0.57cvss 8.8epss 0.01
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a…
- risk 0.57cvss 8.8epss 0.02
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
- risk 0.55cvss 7.5epss 0.47
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.