Description
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: 3.4% Low
KEV: No
Impact: Remote Code Execution via OS command injection
Action: Apply Firmware Update
AI Analysis

Impact

A flaw in the iux_set.cgi component of EFM ipTIME C200E firmware 1.094 allows a remote attacker to inject arbitrary operating system commands. The vulnerability arises from an unsanitized input field that is passed to the underlying shell, resulting in a classic OS command injection weakness as classified by CWE-77 and CWE-78. An attacker who successfully exploits this flaw can run arbitrary code on the router, compromising confidentiality, integrity, or availability of the affected device.

Affected Systems

The issue affects EFM ipTIME C200E routers that are running firmware version 1.094. No other firmware versions or related products are indicated as impacted by the CVE.

Risk and Exploitability

The CVSS score of 9.4 denotes critical severity. The EPSS score of 3% indicates that, at the time of assessment, the vulnerability is not extremely likely to be exploited but remains a real threat. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote – a malicious HTTP request to the /iux_set.cgi endpoint can trigger the injection. The CVE text does not specify whether authentication is required, so it is unclear if the vulnerability is exploitable without prior authentication.

Generated by OpenCVE AI on September 25, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check if the device’s firmware is 1.094 or a known vulnerable version; if so, investigate whether a newer firmware release from the vendor addresses the command‑injection flaw.
  • If a patched firmware version is available, perform the upgrade according to the manufacturer’s update procedure to eliminate the injection point.
  • Until a patch is available, restrict external access to the router by placing it behind a firewall, disabling the Web admin interface from outside the trusted network, or blocking the /iux_set.cgi URI. Additionally, monitor logs for unexpected activity on that endpoint to detect attempted exploitation.

Generated by OpenCVE AI on September 25, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Title EFM ipTIME C200E System Setup iux_set.cgi os command injection
First Time appeared Efm
Efm iptime C200e
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:efm:iptime_c200e:*:*:*:*:*:*:*:*
Vendors & Products Efm
Efm iptime C200e
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Efm Iptime C200e
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T19:05:36.664Z

Reserved: 2026-09-14T05:23:56.580Z

Link: CVE-2026-90847

cve-icon Vulnrichment

Updated: 2026-09-15T19:05:33.529Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T01:16:54.423

Modified: 2026-09-15T19:17:46.767

Link: CVE-2026-90847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:30:20Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')