Impact
A weakness in the function httpcon_check_session_url within the Session Validation Handler of the EFM ipTIME T16000M router allows an attacker to manipulate requests and bypass authentication checks. The vulnerability can be exploited remotely, as the attack vector uses HTTP/HTTPS traffic. Once authenticated improperly, an attacker could potentially gain full administrative access to the device. The exploit code has already been made available to the public, increasing the likelihood of widespread attacks. The vendor did not respond to the disclosure.
Affected Systems
The vulnerability affects EFM ipTIME T16000M routers running firmware 14.20.2. No other versions or additional vendor products are listed as impacted.
Risk and Exploitability
With a CVSS score of 10, this flaw is rated as critical. The EPSS score of 1% indicates a low but non-zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Yet the public availability of exploit code and the ability to target the router over the network make exploitation highly feasible. Based on the description, the likely attack vector is remote over HTTP/HTTPS, requiring only network connectivity to the device.
OpenCVE Enrichment