CVE-2026-82778
Received Received - Intake

Directory Listing Exposure in CONPROSYS PAC Series

Vulnerability report for CVE-2026-82778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: JPCERT/CC

Description

An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
conprosys pac_series *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-548 The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an exposure of information through directory listing in CONPROSYS PAC Series. It allows a remote unauthenticated attacker to access a specific URL and obtain a directory list without needing authentication.

Detection Guidance

To detect this vulnerability, check if directory listing is enabled on CONPROSYS PAC Series devices by accessing URLs like /cgi-bin/ or /htdocs/ via web browser or tools like curl. Example: curl -I http://<target-ip>/cgi-bin/

Impact Analysis

An attacker could exploit this to view sensitive directory contents, potentially exposing files or system information that could aid further attacks. This may lead to unauthorized data access or system compromise depending on the exposed data.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by exposing sensitive data without authorization. Organizations may face penalties for failing to protect personal or health information due to insufficient access controls.

Mitigation Strategies

Disable directory listing in the web server configuration of CONPROSYS PAC Series devices. Restrict access to sensitive URLs and ensure authentication is required for all administrative interfaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart