Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-19977: EFM ipTIME A3004T Session Validation: Improper Authentication Risk

CVE-2026-19977 · published 18 days ago
Summary

A security issue exists in EFM ipTIME A3004T 14.19.0 that allows unauthorized access. This could happen if an attacker manipulates the session validation process. We recommend checking with the vendor for an update or patch to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
efm iptime a3004t 14.19.0
Original advisory text
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in i...
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Severity
9.3 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-19977 · MITRE
Monitor software like this
Free during beta