← Terug naar overzicht

A vulnerability has been identified in EFM ipTIME T16000M firmware version 14.20.2. The flaw resides in the function httpcon_check_session_url within the Session Validation Handler component. The vulnerability leads to improper authentication, allowing remote attackers to bypass session validation. Exploitation is possible remotely without physical access to the device. A public exploit has already been released, increasing the risk of active attacks. The vulnerability was responsibly disclosed to the vendor, but no response was received. The public availability of the exploit significantly raises the threat level for affected devices. Network devices like routers are critical infrastructure components, making this a high-priority issue. Organizations using the affected firmware version should apply mitigations or monitor for exploitation attempts.

Affected products

  • EFM ipTIME T16000M 14.20.2

Related CVE's

  • CVE-2026-78167

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities