What is CVE-2026-19379?
An OS command injection vulnerability was found in the CGI endpoint (/cgi/d.cgi) of EFM ipTIME AX8004M 15.09.0, specifically in the popen function via the `fname` argument. This vulnerability allows remote exploitation. Users should update to the latest firmware.
Azərbaycanca: EFM ipTIME AX8004M 15.09.0 cihazının CGI endpointində (/cgi/d.cgi) popen funksiyasında `fname` arqumenti ilə OS command injection zəifliyi aşkarlanıb. Bu zəiflik uzaqdan hücum etməyə imkan verir. Cihazınızı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What vulnerability was found in my EFM ipTIME AX8004M device?
An OS command injection vulnerability exists in the popen function via the `fname` argument in the `/cgi/d.cgi` endpoint of version 15.09.0.
How can I protect against CVE-2026-19379?
It is recommended to update your device to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.