Description
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-24
Score: 10 Critical
EPSS: 1.0% Low
KEV: No
Impact: Improper Authentication leading to potential remote control of the device
Action: Apply Patch
AI Analysis

Impact

A weakness in the function httpcon_check_session_url within the Session Validation Handler of the EFM ipTIME T16000M router allows an attacker to manipulate requests and bypass authentication checks. The vulnerability can be exploited remotely, as the attack vector uses HTTP/HTTPS traffic. Once authenticated improperly, an attacker could potentially gain full administrative access to the device. The exploit code has already been made available to the public, increasing the likelihood of widespread attacks. The vendor did not respond to the disclosure.

Affected Systems

The vulnerability affects EFM ipTIME T16000M routers running firmware 14.20.2. No other versions or additional vendor products are listed as impacted.

Risk and Exploitability

With a CVSS score of 10, this flaw is rated as critical. The EPSS score of 1% indicates a low but non-zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Yet the public availability of exploit code and the ability to target the router over the network make exploitation highly feasible. Based on the description, the likely attack vector is remote over HTTP/HTTPS, requiring only network connectivity to the device.

Generated by OpenCVE AI on August 24, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Immediately upgrade the router firmware to a patched version as soon as one is released by EFM.
  • If a patch is not yet available, block external access to the HTTP/HTTPS ports that expose the session validation endpoint using the router’s firewall or an external network firewall.
  • Change the default administrative credentials and enforce strong, unique passwords for all user accounts.
  • Monitor network traffic and router logs for repeated unauthorized access attempts and investigate any anomalies promptly.

Generated by OpenCVE AI on August 24, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Iptime
Iptime t16000m
Vendors & Products Iptime
Iptime t16000m

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication
First Time appeared Efm
Efm iptime T16000m
Weaknesses CWE-287
CPEs cpe:2.3:a:efm:iptime_t16000m:*:*:*:*:*:*:*:*
Vendors & Products Efm
Efm iptime T16000m
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Efm Iptime T16000m
Iptime T16000m
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-24T18:00:21.875Z

Reserved: 2026-08-23T14:08:43.212Z

Link: CVE-2026-78167

cve-icon Vulnrichment

Updated: 2026-08-24T18:00:12.748Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T02:17:04.300

Modified: 2026-08-24T18:17:26.737

Link: CVE-2026-78167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:12Z

Weaknesses