Sceawere

Vulnerability Detail

CVE-2026-78167UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ipTIME T16000M Improper Authentication

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
3h ago
Vendor
EFM
Product
ipTIME T16000M
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-24T02:17:04.300Z",
  "pubdate": "2026-08-24T02:17:04.300Z",
  "executiveSummary": "A vulnerability classified as improper authentication has been identified in the EFM ipTIME T16000M router running firmware version 14.20.2.\nThe flaw resides within the Session Validation Handler component, specifically inside the httpcon_check_session_url function.\nThis security deficiency allows remote attackers to bypass authentication controls and interact with the device without valid credentials.\nThe risk implications are significant because unauthorized remote actors can manipulate session validation mechanisms to execute unauthorized actions on the administration interface.\nPublicly available exploit code lowers the barrier to entry for malicious actors, increasing the likelihood of active exploitation in the wild.\nThe vendor was notified of the disclosure but failed to provide any response or official patch, leaving deployments exposed to potential compromise unless compensating controls are implemented.",
  "technicalDetails": "The vulnerability is rooted in flawed logic within the httpcon_check_session_url function of the Session Validation Handler component in EFM ipTIME T16000M firmware version 14.20.2.\nThe root cause stems from improper authentication checks where the application fails to adequately verify the authenticity or existence of a user session during HTTP request processing.\nThe affected component is exposed directly to the network, allowing remote attackers to interact with the HTTP interface without requiring prior authentication or valid session tokens.\nThe attack flow proceeds as follows: an unauthenticated remote attacker crafts a malicious HTTP request directed at the vulnerable interface managed by httpcon_check_session_url.\nBecause the function fails to correctly validate the session parameters, the application incorrectly interprets the incoming request as belonging to an authenticated, authorized session.\nThis bypasses the intended access control boundary enforced by the Session Validation Handler, granting the attacker unauthorized access to restricted functionalities.\nThe exploitation method leverages the publicly available exploit payload, which interacts directly with the exposed web service endpoints.\nNo special privileges or prior authentication are required to initiate the attack, provided the target device's administration or HTTP interface is reachable over the network.\nPost-exploitation impact includes complete administrative compromise of the affected routing device, potential interception or tampering of network traffic, modification of system configurations, and pivoting into the internal network protected by the router."
}
CVE-2026-78167: ipTIME T16000M Improper Authentication (CRITICAL Severity, CVSS: 10.0) - Sceawere