CVE-2026-1741 describes a backdoor vulnerability in EFM ipTIME A8004T 14.18.2, specifically within the Debug Interface's httpcon_check_session_url function when processing the 'cmd' argument. This allows for remote manipulation. The vulnerability carries a CVSS score of 6.6 (Medium), indicating a high attack complexity and difficult exploitability, but with high impact on confidentiality, integrity, and availability once exploited. An attacker would require high privileges (PR:H) to initiate the attack. While the exploit has been publicly disclosed, there are no known Metasploit, Nuclei, or ExploitDB modules, and it is not currently listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.18.2CPE matchmatch criteria | cpe:2.3:o:iptime:a8004t_firmware:14.18.2:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.