Junglewise Threat Intelligence

CVE-2026-90847: EFM ipTIME C200E OS command injection in iux_set.cgi

CVE-2026-90847 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

The EFM ipTIME C200E is a network appliance used for connectivity and system management. A vulnerability in its web-based system setup interface allows remote attackers to inject arbitrary OS commands without authentication, potentially leading to complete device compromise and unauthorized access to network traffic.

Technical details

The vulnerability is an OS command injection flaw in the iux_set.cgi component of the EFM ipTIME C200E system setup interface. The vulnerability exists in an unknown function that fails to properly sanitize user input passed through the web interface. An attacker can exploit this remotely by sending a crafted request containing shell metacharacters to execute arbitrary commands with device privileges. No authentication is required to exploit this vulnerability. The exploit has been publicly disclosed.

Affected products

  • EFM ipTIME C200E 1.094

Timeline

  • 2026-09-15: disclosed
  • other: Exploit publicly disclosed

References