Sceawere

Vulnerability Detail

CVE-2026-78168UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

EFM ipTIME T24000M Improper Authentication

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
EFM
Product
ipTIME T24000M
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-24T02:17:04.480Z",
  "pubdate": "2026-08-24T02:17:04.480Z",
  "executiveSummary": "A security vulnerability has been identified in EFM ipTIME T24000M routers up to version 14.20.0, specifically within the Session Validation Handler component. The flaw resides in the httpcon_check_session_url function and results in improper authentication.\nThis vulnerability allows remote attackers to bypass authentication mechanisms and interact with the device without proper validation. The lack of adequate security controls poses a high risk to affected systems, potentially exposing device management interfaces and sensitive internal functionalities to unauthorized third parties.\nThe exploit for this vulnerability has been publicly disclosed, increasing the likelihood of active exploitation in the wild. Despite early notification, the vendor has failed to respond or provide an official security patch, leaving systems exposed unless manual hardening measures are implemented.\nAttackers do not require prior authentication or privileged access to execute the attack, provided they have network connectivity to the vulnerable service interface. Exploitation relies on manipulating the session validation logic to bypass access restrictions enforced by the web management interface.",
  "technicalDetails": "The vulnerability is caused by flawed session validation logic within the httpcon_check_session_url function of the Session Validation Handler component in EFM ipTIME T24000M up to version 14.20.0.\nThe root cause stems from improper implementation of authentication checks, where incoming HTTP requests are inadequately verified for valid session state or tokens before granting access to restricted functionalities.\nThe affected component is exposed over the network via the device's web management interface, typically accessible via HTTP or HTTPS protocols. Because the vulnerability can be triggered remotely without authentication or privileged access, an unauthenticated attacker can interact directly with the vulnerable endpoint.\nDuring an attack, the adversary sends a maliciously crafted HTTP request targeting the routine handled by httpcon_check_session_url. Due to insufficient validation of session parameters, the application incorrectly assumes the request originates from an authenticated user or fails to validate the session state entirely.\nThis logic flaw allows the attacker to bypass authentication checks and successfully invoke administrative or restricted actions normally reserved for authorized sessions.\nThe post-exploitation impact includes unauthorized access to device settings, potential manipulation of network configurations, and complete compromise of the router's management plane. Given that public exploit code is available, threat actors can automate the attack vector against exposed devices."
}
CVE-2026-78168: EFM ipTIME T24000M Improper Authentication (CRITICAL Severity, CVSS: 9.8) - Sceawere