CVE-2026-19977
10.0EFM · ipTIME A3004T
A session validation vulnerability in EFM ipTIME A3004T 14.19.0 allows unauthenticated remote attackers to bypass authentication mechanisms via the httpcon_check_session_url function.
Executive summary
A critical improper authentication vulnerability in EFM ipTIME A3004T 14.19.0 allows unauthenticated remote attackers to bypass security controls.
Vulnerability
The flaw exists in the httpcon_check_session_url function within the session validation component. It allows an unauthenticated attacker to manipulate session checks, effectively bypassing the authentication process entirely.
Business impact
This vulnerability carries a CVSS score of 10.0, representing the highest possible severity. An attacker can gain unauthorized, full administrative access to the device, facilitating complete system takeover. This could lead to total compromise of network traffic, credential theft, or the use of the device as a persistent beachhead within the internal network.
Remediation
Immediate Action: Monitor the EFM website for emergency firmware patches, as no official fix is currently available from the vendor.
Proactive Monitoring: Implement strict logging for all administrative login attempts and session creation events on the device.
Compensating Controls: Isolate the device from external networks using a hardware firewall, ensuring that the web management interface is inaccessible to untrusted sources.
Exploitation status
Public Exploit Available: No (No confirmed weaponized exploit is documented in the provided data.)
Analyst recommendation
The severity of this authentication bypass necessitates immediate isolation of affected devices. Administrators should prioritize disabling remote management features or restricting access to the web interface via network ACLs until the vendor provides a secure firmware update.