CVE-2026-82791: Contec Co., Ltd Can-2-USB
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Affected products
- Contec Co., Ltd Can-2-USB: before 2.20 (fixed in 2.20)
- Contec Co., Ltd Can-2-Wf: before 2.20 (fixed in 2.20)
Published 2026-09-14. Last modified 2026-09-16.