Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contec

First CVE: Mar 14, 2014Active for: 12 yearsTotal CVEs: 46
59.8
VTI Score
TOP TARGET

Contec manufactures industrial control and automation products, with a concentrated exposure across embedded HMI systems and compact programmable controllers such as its SV-CPT-MC310 series. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the appeal of industrial systems as targets for operational disruption. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, and unrestricted file upload—cluster around input handling and access control in web-facing interfaces, typical of legacy or simplified embedded management consoles. Defenders managing these systems should treat Contec advisories as priority and isolate affected devices from untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
2.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Contec over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2014
12 years ago
Most Recent CVE
Jul 1, 2025
388 days ago

Products(53 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-29303CRITICAL
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
May 12, 20229.898YESYES
CVE-2023-23333CRITICAL
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
Feb 6, 20239.894NOYES
CVE-2022-44456CRITICAL
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a
Dec 19, 20229.869NONO
CVE-2022-29298HIGH
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
May 12, 20227.568NOYES
CVE-2023-29919CRITICAL
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
May 23, 20239.166NOYES
CVE-2022-40881CRITICAL
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
Nov 17, 20229.857NOYES
CVE-2023-28651MEDIUM
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege conf
Jun 1, 20234.848NONO
CVE-2023-29154HIGH
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execut
Jun 1, 20237.245NONO
CVE-2021-20660MEDIUM
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
Feb 24, 20216.143NONO
CVE-2023-40924HIGH
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
Sep 8, 20237.533NOYES
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
35%
46%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (4.3%)
Network41 (89.1%)
Unknown1 (2.2%)
Physical0 (0.0%)
Adjacent Network2 (4.3%)
Attack Complexity
Low44 (95.7%)
High1 (2.2%)
Unknown1 (2.2%)
User Interaction
None39 (84.8%)
Unknown1 (2.2%)
Required6 (13.0%)
Privileges Required
Low19 (41.3%)
High5 (10.9%)
None21 (45.7%)
Unknown1 (2.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
1 CVE
2.2% of CVEs· 99th percentile
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
7 CVEs
15.2% of CVEs· 97th percentile
ExploitDB
3 CVEs
6.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contec.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contec — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contec's Products

View all 4 CNAs →

Top CWEs