VulnerabilityAnalyzed
CVE-2026-1742
A vulnerability was identified in EFM ipTIME A8004T 14.18.2.
LOW 2.0EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component VPN Service. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-434
- Affected
- iptime/a8004t firmware
- Source
- cna@vuldb.com
References
- https://github.com/LX-LX88/cve/issues/29Broken Link, Issue Tracking
- https://vuldb.com/?ctiid.343641Permissions Required, VDB Entry
- https://vuldb.com/?id.343641Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.741450Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.