CVE-2026-19379
7.3EFM · ipTIME AX8004M
The EFM ipTIME AX8004M router is vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary system commands.
Executive summary
A critical OS command injection vulnerability in the EFM ipTIME AX8004M router allows unauthenticated remote attackers to compromise the integrity and availability of the device.
Vulnerability
The device suffers from an OS command injection flaw (CWE-78), which allows an unauthenticated remote attacker to inject and execute arbitrary system commands via the network interface.
Business impact
The CVSS score of 7.3 classifies this as a high-severity issue. Successful exploitation grants an attacker the ability to execute unauthorized commands on the router, potentially leading to full device takeover, network interception, or further lateral movement into the internal network, which poses a significant threat to organizational security and data confidentiality.
Remediation
Immediate Action: Monitor official EFM support channels for the release of a firmware update and apply it immediately upon availability.
Proactive Monitoring: Review device access logs for unusual system calls or command execution patterns that deviate from standard operation.
Compensating Controls: Restrict management interface access to trusted internal IP addresses and employ a firewall to block unauthorized inbound traffic to the router management port.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the ability for unauthenticated attackers to execute arbitrary code, this vulnerability presents a high risk to network perimeter security. Administrators should restrict access to the device management interface immediately and prioritize applying the vendor patch once it is released.