Junglewise Threat Intelligence

CVE-2026-82765: Contec FLEXLAN series path traversal via FTP

CVE-2026-82765 · Severity: high · CVSS 8.1 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec FLEXLAN industrial networking devices contain a path traversal vulnerability that allows an attacker with FTP access to read and modify arbitrary files on the device. This affects critical network infrastructure used in manufacturing and industrial automation environments, potentially enabling attackers to alter system configuration, access sensitive data, or compromise device functionality.

Technical details

A path traversal vulnerability (CWE-23) exists in the FTP interface of Contec FLEXLAN series devices, allowing authenticated FTP users to bypass directory restrictions and access arbitrary files on the server filesystem. The vulnerability requires FTP access credentials but no additional user interaction. An attacker can exploit this to read sensitive files (configuration, logs, credentials) and write/modify files to alter device behavior or inject malicious content. Firmware updates are available for affected series: FX5000 series (prior to 1.12.00), FX4000 series (prior to 1.14.00), and FX3000 series (prior to 1.20.00).

Affected products

  • Contec FX5000 series prior to 1.12.00
  • Contec FX4000 series prior to 1.14.00
  • Contec FX3000 series prior to 1.20.00

Timeline

  • 2026-09-14: disclosed

References

Related threats