← Terug naar overzicht

A vulnerability has been identified in EFM ipTIME T16000M firmware version 14.20.2. The flaw resides in the function httpcon_check_session_url within the Session Validation Handler component. The vulnerability enables improper authentication, allowing remote attackers to bypass session validation. The exploit has been publicly disclosed and is available for use in attacks. The vendor was notified early in the disclosure process but did not respond. This represents a critical risk as the exploit is publicly available and the vendor has not issued a patch or acknowledgment. The affected device is a network switch, making this a significant concern for network infrastructure security.

Affected products

  • EFM ipTIME T16000M 14.20.2

Related CVE's

  • CVE-2026-78167

Categories

  • Identity & Access
  • Network Infrastructure
  • Zero-Day Vulnerabilities