Loading market data...
← Back to CVE feed

CVE-2026-19977

CRITICAL CVSS 10.0 View on NVD ↗

Description

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published: Aug 17, 2026 03:16 UTC Modified: Aug 17, 2026 03:16 UTC