Sceawere
Vulnerability Detail
CVE-2026-78168UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
EFM ipTIME T24000M Improper Authentication
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- EFM
- Product
- ipTIME T24000M
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-24T02:17:04.480Z",
"pubdate": "2026-08-24T02:17:04.480Z",
"executiveSummary": "A security vulnerability has been identified in EFM ipTIME T24000M routers up to version 14.20.0, specifically within the Session Validation Handler component. The flaw resides in the httpcon_check_session_url function and results in improper authentication.\nThis vulnerability allows remote attackers to bypass authentication mechanisms and interact with the device without proper validation. The lack of adequate security controls poses a high risk to affected systems, potentially exposing device management interfaces and sensitive internal functionalities to unauthorized third parties.\nThe exploit for this vulnerability has been publicly disclosed, increasing the likelihood of active exploitation in the wild. Despite early notification, the vendor has failed to respond or provide an official security patch, leaving systems exposed unless manual hardening measures are implemented.\nAttackers do not require prior authentication or privileged access to execute the attack, provided they have network connectivity to the vulnerable service interface. Exploitation relies on manipulating the session validation logic to bypass access restrictions enforced by the web management interface.",
"technicalDetails": "The vulnerability is caused by flawed session validation logic within the httpcon_check_session_url function of the Session Validation Handler component in EFM ipTIME T24000M up to version 14.20.0.\nThe root cause stems from improper implementation of authentication checks, where incoming HTTP requests are inadequately verified for valid session state or tokens before granting access to restricted functionalities.\nThe affected component is exposed over the network via the device's web management interface, typically accessible via HTTP or HTTPS protocols. Because the vulnerability can be triggered remotely without authentication or privileged access, an unauthenticated attacker can interact directly with the vulnerable endpoint.\nDuring an attack, the adversary sends a maliciously crafted HTTP request targeting the routine handled by httpcon_check_session_url. Due to insufficient validation of session parameters, the application incorrectly assumes the request originates from an authenticated user or fails to validate the session state entirely.\nThis logic flaw allows the attacker to bypass authentication checks and successfully invoke administrative or restricted actions normally reserved for authorized sessions.\nThe post-exploitation impact includes unauthorized access to device settings, potential manipulation of network configurations, and complete compromise of the router's management plane. Given that public exploit code is available, threat actors can automate the attack vector against exposed devices."
}