CVE-2026-19379

7.3

EFM · ipTIME AX8004M

The EFM ipTIME AX8004M router is vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary system commands.

Executive summary

A critical OS command injection vulnerability in the EFM ipTIME AX8004M router allows unauthenticated remote attackers to compromise the integrity and availability of the device.

Vulnerability

The device suffers from an OS command injection flaw (CWE-78), which allows an unauthenticated remote attacker to inject and execute arbitrary system commands via the network interface.

Business impact

The CVSS score of 7.3 classifies this as a high-severity issue. Successful exploitation grants an attacker the ability to execute unauthorized commands on the router, potentially leading to full device takeover, network interception, or further lateral movement into the internal network, which poses a significant threat to organizational security and data confidentiality.

Remediation

Immediate Action: Monitor official EFM support channels for the release of a firmware update and apply it immediately upon availability.

Proactive Monitoring: Review device access logs for unusual system calls or command execution patterns that deviate from standard operation.

Compensating Controls: Restrict management interface access to trusted internal IP addresses and employ a firewall to block unauthorized inbound traffic to the router management port.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the ability for unauthenticated attackers to execute arbitrary code, this vulnerability presents a high risk to network perimeter security. Administrators should restrict access to the device management interface immediately and prioritize applying the vendor patch once it is released.

More EFM CVEs