← Terug naar overzicht

A security vulnerability has been identified in EFM ipTIME T24000M firmware versions up to 14.20.0. The flaw exists in the function httpcon_check_session_url within the Session Validation Handler component. Exploitation of this vulnerability leads to improper authentication, potentially allowing unauthorized access. The attack vector is remote, requiring no physical access to the device. A public exploit has already been disclosed and is available for use. The vendor was notified prior to public disclosure but did not respond. This poses a significant risk to network infrastructure relying on this hardware. No patch or mitigation from the vendor has been confirmed.

Affected products

  • EFM ipTIME T24000M up to 14.20.0

Related CVE's

  • CVE-2026-78168

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure