Impact
A remote attacker can manipulate parameters used by the iux_set.cgi web component, enabling execution of arbitrary operating system commands on the device. The flaw allows remote code execution, which can compromise confidentiality, integrity, and availability of the affected system. The weakness is a classic OS command injection, as identified by CWE-77 and CWE-78.
Affected Systems
The vulnerability affects EFM ipTIME C200E routers running firmware version 1.094. No other versions or products are indicated as impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, likely via HTTP requests to the /iux_set.cgi endpoint, and can be performed without authentication according to the publicly disclosed exploit. Remediation requires firmware updates or mitigations until a patch is released.
OpenCVE Enrichment