Impact
A vulnerability exists in the Hidden Hiddenloginsetup interface of the EFM ipTIME A8004T router firmware 14.18.2. The function httpcon_check_session_url in /cgi/timepro.cgi allows an attacker to bypass authentication and gain unauthorized access. The weakness is a CWE-287 Improper Authentication flaw. Because the flaw is triggered by manipulating input parameters, an attacker can perform it remotely without prior access, potentially exposing sensitive configuration settings.
Affected Systems
This flaw affects only the EFM ipTIME A8004T model running firmware version 14.18.2. No other models or firmware versions are explicitly listed as impacted.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 6.9, indicating moderate severity, and has an EPSS of less than 1 %, suggesting a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Attackers can exploit it remotely to bypass authentication, which could lead to full control over the router’s configuration interface. No special prerequisites are noted beyond the ability to send crafted requests to the device.
OpenCVE Enrichment