CVE-2026-90847
nicheAuthenticated OS Command Injection in EFM ipTIME C200E Router (iux_set.cgi)
EFM Networks' ipTIME C200E router, firmware 1.094, contains an OS command injection vulnerability in an unknown function of the iux_set.cgi script within the System Setup component. A remote attacker triggers the flaw by sending a crafted request to the vulnerable CGI endpoint, causing the router to execute attacker-supplied operating-system commands. Successful exploitation yields full control of the device — arbitrary command execution with high impact on confidentiality, integrity, and availability — though the CVSS 4.0 vector (PR:H) indicates the attacker needs valid high-privilege (administrator) credentials on the router's web interface. Only ipTIME C200E devices running firmware 1.094 are listed as affected. The flaw has been publicly disclosed, but no public proof-of-concept code or confirmed in-the-wild exploitation is known, and it is not on the CISA KEV list.
What to do: Watch for and apply an ipTIME/EFM Networks firmware update for the C200E, since 1.094 is the confirmed vulnerable version and no fixed release is listed yet. In the meantime, keep the router's web administration interface off the internet (restrict management to the LAN or a VPN) and enforce strong, unique admin credentials, since exploitation requires administrator access. Review device logs for unexpected requests to iux_set.cgi or signs of modified system settings.
| EFM Networks (ipTIME) ipTIME C200E | 1.094 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.