Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-19977: EFM ipTIME A3004T Session Validation: Improper Authentication Risk
CVE-2026-19977 · published 18 days ago
Summary
A security issue exists in EFM ipTIME A3004T 14.19.0 that allows unauthorized access. This could happen if an attacker manipulates the session validation process. We recommend checking with the vendor for an update or patch to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| efm | iptime a3004t | 14.19.0 |
Original advisory text
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in i...
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
- https://vuldb.com/vuln/391156 vdb-entry technical-description
- https://vuldb.com/vuln/391156/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-19977 third-party-advisory
- https://vuldb.com/submit/873848 third-party-advisory
- https://github.com/AdminSafe/CVE/issues/1 exploit issue-tracking
Severity
9.3
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta