Backdoor Vulnerability in EFM ipTIME Router 14.18.2
CVE-2026-1741

7.5HIGH

Key Information:

Vendor

Efm

Vendor
CVE Published:
2 February 2026

What is CVE-2026-1741?

A security vulnerability has been identified in the EFM ipTIME A8004T router, specifically in version 14.18.2. This flaw exists within the httpcon_check_session_url function, located in the Debug Interface component's /sess-bin/d.cgi file. The manipulation of the 'cmd' argument creates a potential backdoor, allowing attackers to conduct remote exploitation. Although the intricacy of executing this attack is measured to be high, the exploit has been publicly disclosed, raising concerns for users of affected devices. Despite attempts to inform the vendor of this issue, there has been no response.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ipTIME A8004T 14.18.2

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LX-LX (VulDB User)
.