CVE-2026-82775

Summary

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

Affected Software

VendorProductVersion RangeStatus
Contec Co., Ltd.M2M Gateway Integrated Type CPS-MG341*0 < 4.1.0affected
Contec Co., Ltd.M2M Gateway Configurable type CPS-MGS341*0 < 4.1.0affected
Contec Co., Ltd.M2M Controller Integrated Type CPS-MC3410 < 4.1.0affected
Contec Co., Ltd.M2M Controller Configurable type CPS-MCS341*0 < 4.1.0affected

Weaknesses

  • CWE-548: Exposure of information through directory listing

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References