Improper Authentication in EFM ipTIME A8004T Router by EFM Networks
CVE-2026-1740
6.9MEDIUM
What is CVE-2026-1740?
A vulnerability exists in the EFM ipTIME A8004T router, specifically affecting version 14.18.2. It arises from improper authentication in the httpcon_check_session_url function located in the /cgi/timepro.cgi file of the Hiddenloginsetup Interface component. This flaw allows remote attackers to manipulate authentication processes, potentially leading to unauthorized access. The exploit is publicly known, and despite early disclosure attempts to the vendor, no response has been received regarding remediation.
Affected Version(s)
ipTIME A8004T 14.18.2
