CVE-2026-82765
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-23
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Contec Co., Ltd. FXA5000
- Contec Co., Ltd. FXA5020
- Contec Co., Ltd. FXA5020-[][]
- Contec Co., Ltd. FXE5000
- Contec Co., Ltd. FXE5000-[][]
- Contec Co., Ltd. FXS5000-[][]
- Contec Co., Ltd. FXS5021
- Contec Co., Ltd. FXE4000
Weakness type
Related vulnerabilities
- CVE-2025-64446 — A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
- CVE-2025-55752 — Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
- CVE-2025-34510 — Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
- CVE-2025-52207 — PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbit
- CVE-2026-33494 — Ory Oathkeeper has a path traversal authorization bypass
- CVE-2025-62878 — Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern
- CVE-2025-3365 — Relative Path Traversal in OnlineSuite
- CVE-2025-47445 — WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability