Description
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from an unintended directory listing feature enabled on the web interface of Contec M2M devices. When a remote actor accesses a particular URL, the device returns an unprotected list of files in the requested directory, allowing the actor to view configuration files or other sensitive content without authentication. This flaw corresponds to the CWE‑548 weakness, which exposes data that should remain confidential.

Affected Systems

The flaw affects Contec Co., Ltd. M2M Controller and Gateway product lines, including the Configurable type CPS‑MCS341*, Integrated type CPS‑MC341, Configurable Gateway CPS‑MGS341*, and Integrated Gateway CPS‑MG341*. All firmware revisions highlighted in the vendor security notice for the 2609 10 00 release are presumed vulnerable; no specific sub‑versions are enumerated.

Risk and Exploitability

The reported CVSS score of 5.3 places the issue in the moderate severity range, and no EPSS score is available, making it hard to judge current exploitation prevalence. The flaw is not listed in the CISA KEV catalog. Attackers can leverage the vulnerability remotely without credentials, but the impact is limited to information disclosure rather than code execution or privilege escalation.

Generated by OpenCVE AI on September 14, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released firmware update or security patch for the affected M2M Controller and Gateway devices.
  • Disable directory listing in the device’s web server or configuration settings to prevent unintended enumeration of files.
  • Restrict external access to the device’s management URLs using firewall rules or network segmentation, ensuring only authorized administrative networks can reach them.

Generated by OpenCVE AI on September 14, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Directory Listing Information Disclosure in Contec M2M Gateway and Controller Series

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
Weaknesses CWE-548
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:48.884Z

Reserved: 2026-08-31T02:30:58.277Z

Link: CVE-2026-82775

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:21.495Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:18.970

Modified: 2026-09-14T12:17:47.730

Link: CVE-2026-82775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T10:45:07Z

Weaknesses
  • CWE-548

    Exposure of Information Through Directory Listing