CVE-2026-1740
EFM Networks · ipTIME A8004T Router
A vulnerability in the EFM ipTIME A8004T router firmware version 14 could lead to unauthorized access or system compromise.
Executive summary
The EFM ipTIME A8004T router contains a High-severity vulnerability in version 14 that could allow an attacker to compromise the device and the network it manages.
Vulnerability
This vulnerability was identified in the firmware of the ipTIME A8004T router. With a CVSS score of 7.3, the flaw likely involves a weakness in the web management interface or a network service that allows an attacker to bypass security controls or execute unauthorized commands.
Business impact
A compromised router serves as a gateway for attackers to intercept network traffic, launch internal attacks, or enroll the device into a botnet. The High severity score justifies the urgency, as the router is a critical point of failure for network security.
Remediation
Immediate Action: Update the ipTIME A8004T router firmware to the latest version provided by EFM Networks immediately.
Proactive Monitoring: Check the router's administration logs for unauthorized login attempts or changes to DNS and routing configurations.
Compensating Controls: Disable remote management interfaces on the WAN side and ensure that strong, unique passwords are used for all administrative accounts.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Network edge devices are primary targets for initial access. It is vital to apply the firmware update immediately to prevent attackers from gaining a foothold in your network through this vulnerable router.