ZeroHour

CVE-2026-82768

niche

FTP path traversal in SGA1000 allows arbitrary file read and modification

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-82768 is a path traversal vulnerability (CWE-23) in SGA1000 that is reachable through the product's FTP interface. An attacker who can access the product via FTP — for example, an outsider with reachable FTP access or an insider holding valid FTP credentials — can use directory traversal sequences to escape the intended directory and view or alter arbitrary files on the server. Successful exploitation gives high confidentiality and integrity impact (files can be read and rewritten) with no direct availability impact, reflected in a CVSS v4.0 score of 8.6 (high). Organizations running SGA1000, especially deployments with the FTP service enabled and network-reachable, are affected; the specific affected version range was not stated in the advisory. No public proof-of-concept is known, the flaw is not on CISA's Known Exploited Vulnerabilities list, and there is no evidence of in-the-wild exploitation as of this writing.

What to do: Apply the patched version or firmware that the vendor's JPCERT/JVN advisory specifies for SGA1000 as soon as it is available. Until then, disable the FTP service if it is not required, or restrict it to trusted source addresses with strong, unique account credentials. Review the host's file integrity and FTP logs for anomalous traversal-style path requests or unexpected file modifications.

Affected
SGA1000
Estimated exposure
nicheunknown — plausibly hundreds to low thousands of installations (single-model product; no public install or scan data available) — No active-install counts, market-share figures, or internet-exposure scan data exist for SGA1000; the estimate rests on it being a single specific appliance/software model coordinated through Japan's JPCERT, which typically indicates a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

Weakness
CWE-23
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.