Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-19977Bypass de autenticación en routers ipTIME A3004T

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Ver en NVD

Análisis

Esta vulnerabilidad en los routers ipTIME A3004T permite a atacantes remotos omitir la validación de sesiones y obtener acceso administrativo total sin autenticación. Existe un exploit público disponible y el fabricante no ha emitido parches ni respuestas oficiales hasta el momento. Es fundamental revisar el uso de estos dispositivos en infraestructuras de red y desarrollo.

Roles relevantes

HardwareCyberSecurityLinux

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-287

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Publicada: 17/8/2026, 3:16:50
Última modificación: 17/8/2026, 3:16:50

Referencias

InicioEventosBlogRecursosCursosEquipo