Junglewise Threat Intelligence

CVE-2026-82768: Contec SGA1000 path traversal via FTP

CVE-2026-82768 · Severity: high · CVSS 8.1 · Published 2026-09-14

Technologies: Contec SGA1000. Vendors: Contec.

Executive brief

The SGA1000 is an industrial gateway used in factory automation networks. A path traversal vulnerability allows attackers with FTP access to view and modify arbitrary files on the device, potentially compromising system configuration, operational data, or enabling further attacks on connected industrial systems.

Technical details

The vulnerability is a path traversal (CWE-23) in the SGA1000 product from Contec's FLEXLAN series. An authenticated attacker with FTP access can exploit this flaw to traverse directory structures and read or modify arbitrary files on the server. The attack requires network connectivity to the FTP service and valid FTP credentials, but no additional user interaction. Successful exploitation enables confidentiality and integrity violations. Affected versions are prior to 1.02; users should update to the patched firmware version.

Affected products

  • Contec SGA1000 prior to 1.02

Timeline

  • 2026-09-14: disclosed
  • 2026-09-10: advisory: JVNVU#99009004 published

References

Related threats