CVE-2026-78167
Received Received - Intake

Authentication Bypass in ipTIME T16000M Router

Vulnerability report for CVE-2026-78167, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulDB

Description

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
efm_networks iptime_t16000m 14.20.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authentication flaw in the EFM ipTIME T16000M router version 14.20.2. It allows remote attackers to bypass authentication by manipulating the session validation function httpcon_check_session_url. The issue occurs because the function incorrectly skips authentication checks when the request URL does not start with /sess-bin/. Exploitation enables unauthorized access to the device's admin panel.

Detection Guidance

Check if your ipTIME T16000M router is running firmware version 14.20.2. Inspect network traffic for requests to /cgi/timepro.cgi or /sess-bin/d.cgi. Look for unusual administrative actions or password reset attempts. Use tools like curl to test endpoints: curl -v http://<router-ip>/cgi/timepro.cgi or curl -v http://<router-ip>/sess-bin/d.cgi.

Impact Analysis

This vulnerability allows remote attackers to gain full administrative control of the ipTIME T16000M router without authentication. Attackers can reset the admin password, bypass login restrictions, and execute arbitrary commands with root privileges. This results in complete compromise of the device, enabling network monitoring, data interception, or use as a pivot point for further attacks.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection regulations like GDPR and HIPAA by enabling unauthorized access to network devices that may handle sensitive data. Compromised routers could lead to data breaches, unauthorized data access, or network intrusions, all of which are compliance violations. Organizations using this device must address the flaw to maintain regulatory compliance.

Mitigation Strategies

Isolate the affected router from the network immediately. Disable remote administration features if possible. Update the router to the latest firmware version if an update is available. Monitor network traffic for suspicious activity targeting the router.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78167. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart