CVE-2026-82765
nicheFTP Path Traversal in Contec FX3000/FX4000/FX5000 Series Exposes Device Files
Contec's FX5000, FX4000, and FX3000 series products contain a relative path traversal flaw (CWE-23) in their FTP service, rated high severity with a CVSS 4.0 base score of 8.6. An attacker who can access the product via FTP — which, per the 'low privileges required' scoring, implies having at least basic FTP credentials — can supply traversal sequences in FTP file operations to escape the intended directory. Successful exploitation lets the attacker view and/or alter arbitrary files on the device, enabling theft of configuration data or credentials and tampering that could compromise the integrity and behavior of the deployed unit. Organizations running any of these three Contec product lines with the FTP service reachable are affected; the advisory data does not identify specific fixed versions. There is no known public proof of concept, no observed in-the-wild exploitation, and the CVE is not on CISA's Known Exploited Vulnerabilities list.
What to do: Check Contec's and JPCERT/IPCERT advisories for patched firmware or software for the FX3000, FX4000, and FX5000 series and apply it as soon as a fix is available. In the interim, disable the FTP service if it is not needed, restrict FTP access to trusted hosts or networks via firewall rules, and enforce strong unique FTP credentials. Review FTP logs for anomalous file paths containing traversal patterns and verify the integrity of files and configuration on any device that has been network-exposed.
| Contec FX5000 series | — |
| Contec FX4000 series | — |
| Contec FX3000 series | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
- Weakness
- CWE-23
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.