Executive brief
The EFM ipTIME C200E is a network appliance used for connectivity and system management. A vulnerability in its web-based system setup interface allows remote attackers to inject arbitrary OS commands without authentication, potentially leading to complete device compromise and unauthorized access to network traffic.
Technical details
The vulnerability is an OS command injection flaw in the iux_set.cgi component of the EFM ipTIME C200E system setup interface. The vulnerability exists in an unknown function that fails to properly sanitize user input passed through the web interface. An attacker can exploit this remotely by sending a crafted request containing shell metacharacters to execute arbitrary commands with device privileges. No authentication is required to exploit this vulnerability. The exploit has been publicly disclosed.
Affected products
- EFM ipTIME C200E 1.094
Timeline
- 2026-09-15: disclosed
- other: Exploit publicly disclosed