CVE-2026-1741 Details
Description
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A critical command injection vulnerability has been identified in the EFM ipTIME A8004T router, specifically in the 14.18.2 firmware version. The issue resides within the Debug Interface, in the function httpcon_check_session_url of the file /sess-bin/d.cgi. This vulnerability allows for remote exploitation by manipulating the cmd parameter, which can lead to unauthorized execution of shell commands with root privileges. The vulnerability arises from a logical flaw in session validation, where authentication checks can be bypassed, granting access to restricted functions that facilitate the exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/LX-LX88/cve/issues/28 | [email protected] | Broken LinkIssue Tracking |
| https://vuldb.com/?ctiid.343640 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.343640 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.741423 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| iptime a8004t firmware | 14.18.2 |
CPE
Remediation
| |
| iptime a8004t | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | Initial Analysis | [email protected] |
| Feb 2, 2026 | New CVE Received | [email protected] |