Junglewise Threat Intelligence

CVE-2026-19977: EFM ipTIME A3004T authentication bypass in session validation

CVE-2026-19977 · Severity: critical · CVSS 10 · Published 2026-08-17

Executive brief

The ipTIME A3004T is a residential router used to provide internet connectivity and network management. A flaw in the session validation logic allows unauthenticated remote attackers to bypass login authentication and reset the administrator password, gaining complete control of the device. This gives attackers unfettered access to all network traffic and router configurations.

Technical details

The vulnerability is an authentication bypass in the httpcon_check_session_url function within the Session Validation component of the firmware. The function determines whether to enforce authentication solely by checking if the request URL begins with "/sess-bin/"; requests to other paths like "/cgi/timepro.cgi" bypass the authentication check. This logical flaw allows an unauthenticated remote attacker to directly access the password reset endpoint and invoke administrative functions without credentials. The attack is network-reachable and requires no prior authentication or user interaction. No patch availability information is available; the vendor was contacted early but did not respond.

Affected products

  • EFM ipTIME A3004T 14.19.0

Timeline

  • 2026-08-17: disclosed
  • 2026-06-30: other: Exploit details publicly disclosed on GitHub

References