Impact
A vulnerability exists in EFM ipTIME AX8004M 15.09.0 that allows an attacker to manipulate the 'fname' argument of the /cgi/d.cgi endpoint, triggering the popen function and enabling OS command injection. This flaw permits remote execution of arbitrary system commands, which can compromise the device’s integrity, confidentiality, and availability.
Affected Systems
The affected vendor is EFM, product ipTIME AX8004M, specifically firmware version 15.09.0. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, while the EPSS score is not reported and the vulnerability is not yet in CISA’s KEV catalog. The flaw can be exploited remotely through standard HTTP requests to the device, and the vendor has not released an official fix. Consequently, the risk of exploitation is moderate, particularly for exposed devices.
OpenCVE Enrichment