Description
Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote file read and alter of arbitrary server files via FTP
Action: Assess Impact
AI Analysis

Impact

A path traversal flaw in Contec SGA1000 allows an attacker who can reach the device over FTP to read or modify any file on the server’s filesystem. The flaw permits manipulation of critical configuration or proprietary data, compromising data integrity and confidentiality of the managed resource.

Affected Systems

The vulnerability affects Contec Co., Ltd. SGA1000 devices. No specific firmware or model version is listed in the advisory, so all deployed units manufactured under the SGA1000 line are potentially impacted.

Risk and Exploitability

With a CVSS score of 8.6, the severity is high and the flaw is considered serious. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog. The attacker must have FTP access to the device, which is an unprivileged network interaction but can be sufficient to compromise the server if FTP is enabled for remote users. The attack vector is thus a network-based exploitation over FTP, requiring no additional client‑side payload.

Generated by OpenCVE AI on September 14, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict FTP service to trusted IP addresses or disable FTP entirely if it is not required for operation.
  • Download and install any firmware or security patch released by Contec for SGA1000 once it becomes available.
  • Enable strict file permission checks on the device’s operating system and review audit logs for unauthorized file access events.

Generated by OpenCVE AI on September 14, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Allows Remote FTP-Based File Access in Contec SGA1000

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T06:38:23.553Z

Reserved: 2026-08-31T02:30:58.276Z

Link: CVE-2026-82768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:17.980

Modified: 2026-09-14T07:17:17.980

Link: CVE-2026-82768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T11:30:08Z

Weaknesses
  • CWE-23

    Relative Path Traversal