Description
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in EFM ipTIME AX8004M 15.09.0 that allows an attacker to manipulate the 'fname' argument of the /cgi/d.cgi endpoint, triggering the popen function and enabling OS command injection. This flaw permits remote execution of arbitrary system commands, which can compromise the device’s integrity, confidentiality, and availability.

Affected Systems

The affected vendor is EFM, product ipTIME AX8004M, specifically firmware version 15.09.0. No other versions are listed as impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity, while the EPSS score is not reported and the vulnerability is not yet in CISA’s KEV catalog. The flaw can be exploited remotely through standard HTTP requests to the device, and the vendor has not released an official fix. Consequently, the risk of exploitation is moderate, particularly for exposed devices.

Generated by OpenCVE AI on August 10, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version where the popen/OS command injection flaw is fixed.
  • If an update is unavailable, restrict HTTP/Web interface access to the local network and block external connections using firewall or router ACLs.
  • As a temporary measure, disable the /cgi/d.cgi CGI endpoint or block the fname parameter via web interface configuration or local network rules.

Generated by OpenCVE AI on August 10, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection
First Time appeared Efm
Efm iptime Ax8004m
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:efm:iptime_ax8004m:*:*:*:*:*:*:*:*
Vendors & Products Efm
Efm iptime Ax8004m
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Efm Iptime Ax8004m
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-10T00:00:12.562Z

Reserved: 2026-08-09T15:09:27.518Z

Link: CVE-2026-19379

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T01:30:10Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')