CVE-2026-90847
EFM ipTIME C200E System Setup iux_set.cgi os command injection
CVSS Score
9.1
EPSS Score
2.2%
EPSS Percentile
81th
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
| CWE | CWE-78 CWE-77 |
| Vendor | efm |
| Product | iptime c200e |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for efm iptime c200e
Be the first to know when new critical vulnerabilities affecting efm iptime c200e are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
EFM / ipTIME C200E
1.094
References
vuldb.com: https://vuldb.com/vuln/403400 vuldb.com: https://vuldb.com/vuln/403400/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90847 vuldb.com: https://vuldb.com/submit/925831 drive.google.com: https://drive.google.com/file/d/19WVo2tOImpmSEg3dFsmyB5Rw1aMQXyyd/view?usp=drive_link youtu.be: https://youtu.be/qdFGRSpCiY0
Credits
๐ aissac (VulDB User)