What is CVE-2026-19977?
An improper authentication vulnerability was found in the httpcon_check_session_url function within the Session Validation component of EFM ipTIME A3004T version 14.19.0. This allows for remote exploitation, and a public exploit is available. Immediate firmware update is recommended.
Azərbaycanca: EFM ipTIME A3004T 14.19.0 versiyasında Session Validation komponentinin httpcon_check_session_url funksiyasında autentifikasiya zəifliyi aşkarlanıb. Bu, uzaqdan istismar edilə bilən boşluqdur. İstismar kodu ictimaiyyətə açıq olduğu üçün dərhal firmware yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which device is affected by CVE-2026-19977?
CVE-2026-19977 affects the EFM ipTIME A3004T version 14.19.0.
Is there any exploit code available for CVE-2026-19977?
Yes, a public exploit is available for CVE-2026-19977.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.