HIGH

CVE-2026-19379

2026-08-10 CVSS v3.1
CVSS
7.3

Description

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Weakness (CWE)

CWE-77 Command Injection
CWE-78 OS Command Injection

EPSS Score

1.66%
Probability of exploitation in next 30 days
75.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE