Description
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-24
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability enables remote manipulation of the httpcon_check_session_url function within the Session Validation Handler, allowing an attacker to bypass authentication checks. This flaw can lead to unauthorized access to the device and any services that rely on authenticated sessions, potentially compromising device configuration and network traffic. The weakness is classified as Improper Authentication (CWE-287).

Affected Systems

Affected is the EFM ipTIME T24000M router, with firmware versions up to and including 14.20.0 vulnerable. No newer firmware version is specified as fixed, so all builds from the initial release through 14.20.0 are impacted.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The exploit is publicly disclosed and can be performed remotely, but no exploit probability score is available. The vulnerability is not listed in CISA’s KEV catalog, yet the lack of a vendor response and the existence of a remote attack path keep the risk high. Attackers can exploit the flaw without needing privileged access or physical proximity, emphasizing the need for immediate remediation.

Generated by OpenCVE AI on August 24, 2026 at 03:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a release that fixes the authentication bypass, as soon as a vendor patch becomes available.
  • If the firmware update is delayed, block or sandbox the httpcon_check_session_url endpoint from external networks to prevent unauthorized session validation calls.
  • Apply any vendor-supplied configuration changes that enforce proper session checks, and isolate the device on a separate network segment with strict firewall rules to limit potential lateral movement.

Generated by OpenCVE AI on August 24, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication
First Time appeared Efm
Efm iptime T24000m
Weaknesses CWE-287
CPEs cpe:2.3:a:efm:iptime_t24000m:*:*:*:*:*:*:*:*
Vendors & Products Efm
Efm iptime T24000m
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Efm Iptime T24000m
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-27T14:37:28.365Z

Reserved: 2026-08-23T14:09:41.997Z

Link: CVE-2026-78168

cve-icon Vulnrichment

Updated: 2026-08-27T13:31:57.789Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T02:17:04.480

Modified: 2026-08-27T17:20:34.833

Link: CVE-2026-78168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T05:30:12Z

Weaknesses