CVE-2026-78168

9.8

EFM · ipTIME T24000M

A session validation vulnerability in EFM ipTIME T24000M allows remote, unauthenticated attackers to bypass authentication controls via the httpcon_check_session_url function.

Executive summary

A critical authentication bypass vulnerability in the EFM ipTIME T24000M router allows unauthenticated remote attackers to gain unauthorized access to the device.

Vulnerability

This is an improper authentication flaw (CWE-287) located in the Session Validation Handler component. The vulnerability can be triggered remotely by an unauthenticated attacker to bypass session checks.

Business impact

The CVSS score of 9.8 reflects the high severity of this flaw, as it allows full compromise of the device without requiring user interaction or credentials. Successful exploitation could lead to total loss of confidentiality, integrity, and availability for the affected network gateway, potentially facilitating lateral movement into the internal network.

Remediation

Immediate Action: Update the firmware of the EFM ipTIME T24000M to the latest available version provided by the vendor.

Proactive Monitoring: Review device access logs for unauthorized administrative login attempts and monitor for anomalous traffic originating from the management interface.

Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses using firewall rules, and disable remote management features if they are not strictly required.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity of this authentication bypass, administrators must prioritize patching the affected routers immediately. If immediate patching is not feasible, ensure the management interface is not exposed to the public internet to prevent external exploitation.

More EFM CVEs