Sceawere

Vulnerability Detail

CVE-2026-82775UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CONPROSYS Directory Listing Information Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
M2M Gateway Integrated Type CPS-MG341*
Attack Type
Exposure of information through directory listing
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-14T07:17:18.970Z",
  "pubdate": "2026-09-14T07:17:18.970Z",
  "executiveSummary": "A directory listing vulnerability exists within the CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series, classified as an information exposure flaw.\nThe vulnerability allows remote, unauthenticated attackers to retrieve file and directory structures from the target system's web server.\nThe root cause lies in improper web server configuration, where directory browsing is enabled for specific endpoints.\nAn attacker can exploit this by sending a crafted HTTP request to a designated URL, bypassing authentication mechanisms to enumerate sensitive filesystem data.\nSuccessful exploitation results in unauthorized information disclosure, which could reveal configuration files, backup data, or internal system architecture details, potentially facilitating further sophisticated attacks.\nThe risk is elevated because the vulnerability requires no authentication and can be exploited remotely over the network, providing an attacker with reconnaissance capabilities essential for identifying targets for secondary exploits.",
  "technicalDetails": "The vulnerability is characterized as an Information Exposure through Directory Listing, typically associated with CWE-548. This flaw originates from a misconfiguration of the embedded web server running on the CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series devices.\nThe root cause of this vulnerability is the failure to disable directory indexing on the server, which results in the web server automatically generating a directory listing page when a user navigates to a directory that lacks a designated index file (e.g., index.html).\nIn terms of attack flow, the exploitation process is trivial and does not require elevated privileges or pre-existing authentication. An attacker initiates the process by identifying the target device's web interface. Upon identifying a vulnerable URL endpoint, the attacker sends a standard HTTP GET request to that directory path. The web server responds by returning a machine-readable directory listing of the files and subdirectories located within that path.\nThe impact of this vulnerability is significant in the context of industrial and M2M environments. By enumerating the contents of the device's web root or other accessible system directories, an attacker can gain insight into the device's internal structure, software versioning, and configuration metadata. This information disclosure provides critical intelligence that can be leveraged to identify additional vulnerabilities, such as hardcoded credentials or private configuration parameters that might be stored in plain text.\nThe exposure is not limited by user authorization; the web server processes the request as a legitimate query and responds with the full directory structure, effectively bypassing access controls that might otherwise protect sensitive administrative interfaces. The lack of authentication requirements makes this a highly accessible entry point for initial reconnaissance within an OT/ICS network segment.\nPost-exploitation, the information gathered allows the adversary to map the attack surface effectively. Furthermore, the ability to read configuration files may reveal session tokens, network settings, or API keys, which are often stored within web-accessible directories in poorly secured embedded firmware. This information leakage significantly lowers the barrier for subsequent, more destructive exploitation efforts, potentially leading to unauthorized control or further compromise of the M2M infrastructure."
}
CVE-2026-82775: CONPROSYS Directory Listing Information Exposure (MEDIUM Severity, CVSS: 4.3) | Sceawere