Impact
The vulnerability originates from an unintended directory listing feature enabled on the web interface of Contec M2M devices. When a remote actor accesses a particular URL, the device returns an unprotected list of files in the requested directory, allowing the actor to view configuration files or other sensitive content without authentication. This flaw corresponds to the CWE‑548 weakness, which exposes data that should remain confidential.
Affected Systems
The flaw affects Contec Co., Ltd. M2M Controller and Gateway product lines, including the Configurable type CPS‑MCS341*, Integrated type CPS‑MC341, Configurable Gateway CPS‑MGS341*, and Integrated Gateway CPS‑MG341*. All firmware revisions highlighted in the vendor security notice for the 2609 10 00 release are presumed vulnerable; no specific sub‑versions are enumerated.
Risk and Exploitability
The reported CVSS score of 5.3 places the issue in the moderate severity range, and no EPSS score is available, making it hard to judge current exploitation prevalence. The flaw is not listed in the CISA KEV catalog. Attackers can leverage the vulnerability remotely without credentials, but the impact is limited to information disclosure rather than code execution or privilege escalation.
OpenCVE Enrichment