Description
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The weakness arises from an unintended directory‑listing capability built into the web interface of Contec M2M Controller and Gateway devices. When a remote attacker visits a specific URL, the device enumerates the contents of the target directory without requiring authentication. This allows the attacker to view potentially sensitive configuration files or other data that should remain confidential. The flaw is classified as CWE‑548, reflecting an information‑disclosure vulnerability.

Affected Systems

The vulnerability affects Contec Co., Ltd. M2M Controller and Gateway product lines, including the Configurable type CPS‑MCS341*, the Integrated type CPS‑MC341, the Configurable Gateway CPS‑MGS341*, and the Integrated Gateway CPS‑MG341*. No specific firmware versions are listed in the CVE payload; therefore, any firmware revision running the affected web interface could be vulnerable.

Risk and Exploitability

The reported CVSS score of 5.3 places the issue in the moderate severity range, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage the flaw remotely without credentials, but the impact remains confined to information disclosure rather than code execution or privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 15:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released firmware update or security patch for Contec M2M Controller and Gateway devices as documented in the Contec security notice.
  • Disable directory listing in the device’s web server configuration, ensuring that web requests do not reveal directory contents.
  • Restrict external access to the device’s management URLs by configuring firewall rules or implementing network segmentation to limit exposure to authorized administrative networks.

Generated by OpenCVE AI on September 15, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Contec
Contec m2m Controller Configurable Type Cps-mcs341*
Contec m2m Controller Integrated Type Cps-mc341
Contec m2m Gateway Configurable Type Cps-mgs341*
Contec m2m Gateway Integrated Type Cps-mg341*
Vendors & Products Contec
Contec m2m Controller Configurable Type Cps-mcs341*
Contec m2m Controller Integrated Type Cps-mc341
Contec m2m Gateway Configurable Type Cps-mgs341*
Contec m2m Gateway Integrated Type Cps-mg341*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Directory Listing Information Disclosure in Contec M2M Gateway and Controller

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Directory Listing Information Disclosure in Contec M2M Gateway and Controller Series

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Directory Listing Information Disclosure in Contec M2M Gateway and Controller Series

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
Weaknesses CWE-548
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Contec M2m Controller Configurable Type Cps-mcs341* M2m Controller Integrated Type Cps-mc341 M2m Gateway Configurable Type Cps-mgs341* M2m Gateway Integrated Type Cps-mg341*
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:48.884Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82775

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:21.495Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:18.970

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-82775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:46:14Z

Weaknesses
  • CWE-548

    Exposure of Information Through Directory Listing