Impact
The weakness arises from an unintended directory‑listing capability built into the web interface of Contec M2M Controller and Gateway devices. When a remote attacker visits a specific URL, the device enumerates the contents of the target directory without requiring authentication. This allows the attacker to view potentially sensitive configuration files or other data that should remain confidential. The flaw is classified as CWE‑548, reflecting an information‑disclosure vulnerability.
Affected Systems
The vulnerability affects Contec Co., Ltd. M2M Controller and Gateway product lines, including the Configurable type CPS‑MCS341*, the Integrated type CPS‑MC341, the Configurable Gateway CPS‑MGS341*, and the Integrated Gateway CPS‑MG341*. No specific firmware versions are listed in the CVE payload; therefore, any firmware revision running the affected web interface could be vulnerable.
Risk and Exploitability
The reported CVSS score of 5.3 places the issue in the moderate severity range, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage the flaw remotely without credentials, but the impact remains confined to information disclosure rather than code execution or privilege escalation.
OpenCVE Enrichment