contec CVE Vulnerabilities & CVE List (46)

Products (CPE): — CVEs: 46

contec vulnerability overview

Aggregates CVE and security vulnerability intelligence across all contec-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling, vendor risk sql injection, and vendor risk ssrf and related problems; some flaws may lead to vendor impact file overwrite and vendor impact data exposure.

Vulnerability distribution trend (last 24 months)

Showing 2140 of 46 CVEs
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-23333 There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. [email protected] 9.8 99.27% 2023-02-06 2026-06-17
CVE-2023-22324 SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. [email protected] 6.5 1.33% 2023-01-30 2026-06-17
CVE-2023-22373 Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information. [email protected] 5.4 1.87% 2023-01-19 2026-06-17
CVE-2023-22339 Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product. [email protected] 7.5 1.14% 2023-01-19 2026-06-17
CVE-2023-22334 Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack. [email protected] 5.3 0.88% 2023-01-19 2026-06-17
CVE-2023-22331 Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information. [email protected] 7.5 1.01% 2023-01-19 2026-06-17
CVE-2022-44456 CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. [email protected] 9.8 69.88% 2022-12-18 2026-06-17
CVE-2022-44355 SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php. [email protected] 6.1 1.64% 2022-11-29 2026-06-17
CVE-2022-44354 SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. [email protected] 9.8 2.13% 2022-11-29 2026-06-17
CVE-2022-40881 SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php [email protected] 9.8 29.45% 2022-11-16 2026-06-17
CVE-2022-36159 Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware. [email protected] 8.8 0.95% 2022-09-26 2026-06-17
CVE-2022-36158 Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi). [email protected] 8.0 1.43% 2022-09-26 2026-06-17
CVE-2022-35239 The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file. [email protected] 8.8 1.17% 2022-08-16 2026-06-17
CVE-2022-31374 An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file. [email protected] 9.8 2.51% 2022-06-21 2026-06-17
CVE-2022-31373 SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php. [email protected] 6.1 5.12% 2022-06-21 2026-06-17
CVE-2022-29303 KEV SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. [email protected] 9.8 99.92% 2022-05-12 2026-06-17
CVE-2022-29302 SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php. [email protected] 5.5 0.32% 2022-05-12 2026-06-17
CVE-2022-29298 SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. [email protected] 7.5 44.54% 2022-05-12 2026-06-17
CVE-2021-20662 Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information without the access privileges via unspecified vectors. [email protected] 7.5 2.09% 2021-02-24 2026-06-16
CVE-2021-20661 Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors. [email protected] 8.1 2.39% 2021-02-24 2026-06-16
cvelogic Threat Intelligence