๐Ÿ” CVE Alert

CVE-2026-1741

MEDIUM 6.6

EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-912
Vendor efm
Product iptime a8004t
Published Feb 2, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for efm iptime a8004t

Be the first to know when new medium vulnerabilities affecting efm iptime a8004t are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

EFM / ipTIME A8004T
14.18.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.343640 vuldb.com: https://vuldb.com/?ctiid.343640 vuldb.com: https://vuldb.com/?submit.741423 github.com: https://github.com/LX-LX88/cve/issues/28

Credits

๐Ÿ” LX-LX (VulDB User)