Contec manufactures industrial control and automation products, with a concentrated exposure across embedded HMI systems and compact programmable controllers such as its SV-CPT-MC310 series. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the appeal of industrial systems as targets for operational disruption. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, and unrestricted file upload—cluster around input handling and access control in web-facing interfaces, typical of legacy or simplified embedded management consoles. Defenders managing these systems should treat Contec advisories as priority and isolate affected devices from untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contec over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29303CRITICAL SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | May 12, 2022 | 9.8 | 98 | YES | YES |
CVE-2023-23333CRITICAL There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | Feb 6, 2023 | 9.8 | 94 | NO | YES |
CVE-2022-44456CRITICAL CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a | Dec 19, 2022 | 9.8 | 69 | NO | NO |
CVE-2022-29298HIGH SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. | May 12, 2022 | 7.5 | 68 | NO | YES |
CVE-2023-29919CRITICAL SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | May 23, 2023 | 9.1 | 66 | NO | YES |
CVE-2022-40881CRITICAL SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | Nov 17, 2022 | 9.8 | 57 | NO | YES |
CVE-2023-28651MEDIUM Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege conf | Jun 1, 2023 | 4.8 | 48 | NO | NO |
CVE-2023-29154HIGH SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execut | Jun 1, 2023 | 7.2 | 45 | NO | NO |
CVE-2021-20660MEDIUM Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors. | Feb 24, 2021 | 6.1 | 43 | NO | NO |
CVE-2023-40924HIGH SolarView Compact < 6.00 is vulnerable to Directory Traversal. | Sep 8, 2023 | 7.5 | 33 | NO | YES |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contec.
Media articles that mention a CVE ID that affects a product developed by Contec — matched by CVE ID, not by vendor name.