Impact
A flaw in the iux_set.cgi component of EFM ipTIME C200E firmware 1.094 allows a remote attacker to inject arbitrary operating system commands. The vulnerability arises from an unsanitized input field that is passed to the underlying shell, resulting in a classic OS command injection weakness as classified by CWE-77 and CWE-78. An attacker who successfully exploits this flaw can run arbitrary code on the router, compromising confidentiality, integrity, or availability of the affected device.
Affected Systems
The issue affects EFM ipTIME C200E routers that are running firmware version 1.094. No other firmware versions or related products are indicated as impacted by the CVE.
Risk and Exploitability
The CVSS score of 9.4 denotes critical severity. The EPSS score of 3% indicates that, at the time of assessment, the vulnerability is not extremely likely to be exploited but remains a real threat. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote – a malicious HTTP request to the /iux_set.cgi endpoint can trigger the injection. The CVE text does not specify whether authentication is required, so it is unclear if the vulnerability is exploitable without prior authentication.
OpenCVE Enrichment