Impact
A path traversal flaw in Contec SGA1000 allows an attacker who can reach the device over FTP to read or modify any file on the server’s filesystem. The flaw permits manipulation of critical configuration or proprietary data, compromising data integrity and confidentiality of the managed resource.
Affected Systems
The vulnerability affects Contec Co., Ltd. SGA1000 devices. No specific firmware or model version is listed in the advisory, so all deployed units manufactured under the SGA1000 line are potentially impacted.
Risk and Exploitability
With a CVSS score of 8.6, the severity is high and the flaw is considered serious. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog. The attacker must have FTP access to the device, which is an unprivileged network interaction but can be sufficient to compromise the server if FTP is enabled for remote users. The attack vector is thus a network-based exploitation over FTP, requiring no additional client‑side payload.
OpenCVE Enrichment