CVE-2026-82775
Received Received - Intake

Directory Listing Exposure in CONPROSYS M2M Gateway Series

Vulnerability report for CVE-2026-82775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: JPCERT/CC

Description

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
conprosys m2m_gateway_series *
conprosys m2m_controller_series *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-548 The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an exposure of information through directory listing in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. It allows a remote unauthenticated attacker to access a specific URL and obtain a directory list without needing authentication.

Detection Guidance

To detect this vulnerability, check if directory listing is enabled on CONPROSYS M2M Gateway or Controller Series by accessing URLs like http://[target]/[directory]/ on your network. Use tools like curl or wget to request specific paths and observe if directory contents are returned without authentication.

Impact Analysis

An attacker could exploit this to view sensitive directory contents, potentially exposing configuration files, logs, or other sensitive data stored on the device. This may lead to further attacks if critical files are accessible.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Disable directory listing in the web server configuration for affected CONPROSYS products. Apply patches or updates from the vendor if available. Restrict network access to the device using firewalls or network segmentation until mitigation is complete.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart