A security vulnerability has been identified in EFM ipTIME T24000M devices running firmware up to version 14.20.0. The flaw resides in the function httpcon_check_session_url within the Session Validation Handler component, allowing improper authentication through manipulation of session URL parameters. The vulnerability can be exploited remotely without requiring physical access to the device. A public exploit has already been disclosed and is available for use, raising the risk of active exploitation. The vendor was notified prior to public disclosure but did not respond, leaving users without an official patch or mitigation. This represents a significant risk for network devices deployed in enterprise or home environments. Users of the affected hardware should monitor for firmware updates and consider network-level mitigations in the interim.