CVE-2026-78168
Received Received - Intake

Improper Authentication in ipTIME T24000M Router

Vulnerability report for CVE-2026-78168, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulDB

Description

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
efm iptime_t24000m to 14.20.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78168 is an improper authentication vulnerability in the EFM ipTIME T24000M router up to firmware version 14.20.0. It affects the session validation handler function, allowing remote attackers to bypass authentication by manipulating the httpcon_check_session_url component.

Detection Guidance

Check if your ipTIME T24000M router is running firmware version 14.20.0 or earlier. Inspect network traffic for unauthorized access to the 'Remote Support' feature or attempts to interact with the 'd.cgi' endpoint. Look for suspicious commands being executed, especially those involving root access or system modifications.

Impact Analysis

This vulnerability allows remote attackers to gain unauthorized access to the router, potentially leading to full control over the device. Attackers could execute arbitrary commands as root, steal sensitive data, or use the device as a foothold in a network.

Compliance Impact

This vulnerability allows remote attackers to bypass authentication and execute arbitrary commands as root on the affected device. Such unauthorized access could lead to data breaches, unauthorized data access, or manipulation, which may violate compliance requirements under GDPR (data protection) and HIPAA (protected health information).

Mitigation Strategies

Immediately update the ipTIME T24000M router to the latest firmware version if available. Disable the 'Remote Support' feature in the web interface. Block external access to the router's web interface if not necessary. Monitor for any signs of compromise, such as unauthorized admin password changes or unusual command executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78168. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart