PT-2026-37039 · Efm · Iptime C200

Jfkk

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-7833

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EFM ipTIME C200 versions prior to 1.092
Description A command injection issue exists in the ApplyRestore Endpoint. This occurs within the sub 408F90() function of the '/cgi/iux set.cgi' endpoint when the RestoreFile argument is manipulated. This flaw allows a remote attacker to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/cgi/iux set.cgi' endpoint or avoid using the RestoreFile argument until a patch is available.

Exploit

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7833

Affected Products

Iptime C200