Executive brief
The ipTIME T16000M is a wireless router used in homes and small businesses to provide network connectivity. A flaw in the session validation logic allows attackers to bypass login authentication and reset the administrator password without authorization, potentially giving them complete control of the device. This could enable unauthorized access to network traffic, device configuration, and connected systems.
Technical details
The vulnerability is an authentication bypass resulting from improper path validation in the httpcon_check_session_url function within the Session Validation Handler component. The function incorrectly skips authentication enforcement when the request path does not begin with /sess-bin/, allowing attackers to construct requests to /cgi/timepro.cgi to bypass login checks. Once authenticated enforcement is bypassed, attackers can access hidden password reset functionality and subsequently chain this with a command injection vulnerability in the debug interface (/sess-bin/d.cgi) to achieve remote code execution with root privileges. The attack requires network access to the router's web interface but no prior authentication; a proof-of-concept has been publicly disclosed.
Affected products
- EFM ipTIME T16000M 14.20.2
Timeline
- 2026-08-24: disclosed
- exploited: Proof-of-concept exploit made available publicly; not yet actively exploited in the wild