Impact
The vulnerability enables remote manipulation of the httpcon_check_session_url function within the Session Validation Handler, allowing an attacker to bypass authentication checks. This flaw can lead to unauthorized access to the device and any services that rely on authenticated sessions, potentially compromising device configuration and network traffic. The weakness is classified as Improper Authentication (CWE-287).
Affected Systems
Affected is the EFM ipTIME T24000M router, with firmware versions up to and including 14.20.0 vulnerable. No newer firmware version is specified as fixed, so all builds from the initial release through 14.20.0 are impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The exploit is publicly disclosed and can be performed remotely, but no exploit probability score is available. The vulnerability is not listed in CISA’s KEV catalog, yet the lack of a vendor response and the existence of a remote attack path keep the risk high. Attackers can exploit the flaw without needing privileged access or physical proximity, emphasizing the need for immediate remediation.
OpenCVE Enrichment