ZeroHour

CVE-2026-82765

niche

FTP Path Traversal in Contec FX3000/FX4000/FX5000 Series Exposes Device Files

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Contec's FX5000, FX4000, and FX3000 series products contain a relative path traversal flaw (CWE-23) in their FTP service, rated high severity with a CVSS 4.0 base score of 8.6. An attacker who can access the product via FTP — which, per the 'low privileges required' scoring, implies having at least basic FTP credentials — can supply traversal sequences in FTP file operations to escape the intended directory. Successful exploitation lets the attacker view and/or alter arbitrary files on the device, enabling theft of configuration data or credentials and tampering that could compromise the integrity and behavior of the deployed unit. Organizations running any of these three Contec product lines with the FTP service reachable are affected; the advisory data does not identify specific fixed versions. There is no known public proof of concept, no observed in-the-wild exploitation, and the CVE is not on CISA's Known Exploited Vulnerabilities list.

What to do: Check Contec's and JPCERT/IPCERT advisories for patched firmware or software for the FX3000, FX4000, and FX5000 series and apply it as soon as a fix is available. In the interim, disable the FTP service if it is not needed, restrict FTP access to trusted hosts or networks via firewall rules, and enforce strong unique FTP credentials. Review FTP logs for anomalous file paths containing traversal patterns and verify the integrity of files and configuration on any device that has been network-exposed.

Affected
Contec FX5000 series
Contec FX4000 series
Contec FX3000 series
Estimated exposure
nichelikely hundreds to low thousands of devices deployed or reachable (clearly an estimate; no public scan counts available) — The FX-series are specialized embedded/industrial products from a mid-size Japanese vendor, so deployment volume is inherently limited, and no public Shodan/Censys exposure counts or install figures were available to confirm the number.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

Weakness
CWE-23
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.