Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-19977Authentication bypass in ipTIME A3004T routers

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

View on NVD

Analysis

Esta vulnerabilidad en los routers ipTIME A3004T permite a atacantes remotos omitir la validación de sesiones y obtener acceso administrativo total sin autenticación. Existe un exploit público disponible y el fabricante no ha emitido parches ni respuestas oficiales hasta el momento. Es fundamental revisar el uso de estos dispositivos en infraestructuras de red y desarrollo.

Relevant roles

HardwareCyberSecurityLinux

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-287

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Published: 8/17/2026, 3:16:50 AM
Last modified: 8/17/2026, 3:16:50 AM

References

HomeEventsBlogResourcesCoursesTeam