Impact
The vulnerability is a classic path traversal flaw that allows an attacker to access arbitrary files on the device’s file system. If an adversary can reach the device via the FTP service, they can read or write any file the FTP daemon sees, thereby potentially exposing sensitive configuration data or inserting malicious scripts. The flaw is formally identified as CWE-23.
Affected Systems
Affected systems are Contec’s FX series devices, including the FXA3000, FXA3020, FXA3200, FXA5000, FXA5020, FXE3000, FXE4000, FXE5000, FXS300, FXS4000, FXS4020, and FXS5021. Specific firmware versions are not disclosed in the available data.
Risk and Exploitability
The CVSS score of 8.6 classifies this as a high severity vulnerability. The EPSS score, reported as less than 1%, indicates a very low probability of exploitation; however, the lack of a listing in the CISA KEV catalog means it is not a confirmed, widely exploited vulnerability. Based on the description, it is inferred that the FTP service does not enforce strong authentication, so any exposed FTP port could be targeted from a remote network that has access to the FTP interface. This could allow an attacker to read or modify arbitrary files, compromising confidentiality, integrity, and availability of device data and services.
OpenCVE Enrichment