Junglewise Threat Intelligence

CVE-2026-8234: A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the fil

CVE-2026-8234 · Severity: high · CVSS 8.8 · Published 2026-05-10

Executive brief

A security vulnerability exists in the EFM ipTIME A8004T router, a device used to manage home and office network traffic. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic or use the compromised router to launch further attacks on other devices within the network.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formWifiBasicSet' function within the '/goform/WifiBasicSet' endpoint of EFM ipTIME A8004T firmware version 14.18.2. The root cause is the unsafe use of the 'strcpy' function when processing the 'security_5g' POST parameter, which fails to validate the input length against a fixed 256-byte buffer. A remote attacker can exploit this by sending a specially crafted POST request with an oversized payload. Successful exploitation can lead to memory corruption, allowing for arbitrary code execution or a denial of service (DoS) condition. Although the CVSS vector suggests low privileges are required, the researcher's PoC indicates the vulnerability may be triggerable without authentication. No patch has been released by the vendor at the time of disclosure.

Affected products

  • EFM ipTIME A8004T Router 14.18.2

Timeline

  • 2026-04-21: disclosed: Vulnerability details and PoC published on GitHub.
  • 2026-05-10: advisory: CVE-2026-8234 published.

References