CVE-2026-19977

10.0

EFM · ipTIME A3004T

A session validation vulnerability in EFM ipTIME A3004T 14.19.0 allows unauthenticated remote attackers to bypass authentication mechanisms via the httpcon_check_session_url function.

Executive summary

A critical improper authentication vulnerability in EFM ipTIME A3004T 14.19.0 allows unauthenticated remote attackers to bypass security controls.

Vulnerability

The flaw exists in the httpcon_check_session_url function within the session validation component. It allows an unauthenticated attacker to manipulate session checks, effectively bypassing the authentication process entirely.

Business impact

This vulnerability carries a CVSS score of 10.0, representing the highest possible severity. An attacker can gain unauthorized, full administrative access to the device, facilitating complete system takeover. This could lead to total compromise of network traffic, credential theft, or the use of the device as a persistent beachhead within the internal network.

Remediation

Immediate Action: Monitor the EFM website for emergency firmware patches, as no official fix is currently available from the vendor.

Proactive Monitoring: Implement strict logging for all administrative login attempts and session creation events on the device.

Compensating Controls: Isolate the device from external networks using a hardware firewall, ensuring that the web management interface is inaccessible to untrusted sources.

Exploitation status

Public Exploit Available: No (No confirmed weaponized exploit is documented in the provided data.)

Analyst recommendation

The severity of this authentication bypass necessitates immediate isolation of affected devices. Administrators should prioritize disabling remote management features or restricting access to the web interface via network ACLs until the vendor provides a secure firmware update.

More EFM CVEs