CVE-2026-82775: Contec Co., Ltd m2m Controller Configurable Type Cps-MCS341*

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

Affected products

  • Contec Co., Ltd m2m Controller Configurable Type Cps-MCS341*: before 4.1.0 (fixed in 4.1.0)
  • Contec Co., Ltd m2m Controller Integrated Type Cps-MC341: before 4.1.0 (fixed in 4.1.0)
  • Contec Co., Ltd m2m Gateway Configurable Type Cps-MGS341*: before 4.1.0 (fixed in 4.1.0)
  • Contec Co., Ltd m2m Gateway Integrated Type Cps-MG341*: before 4.1.0 (fixed in 4.1.0)

Published 2026-09-14. Last modified 2026-09-16.