CVE-2026-24498 PUBLISHED

Assigner: krcert
Reserved: 23.01.2026 Published: 27.02.2026 Updated: 27.02.2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through 15.26.8; ipTIME AX3000Q: through 15.26.8; ipTIME AX6000M: through 15.26.8.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor EFM-Networks, Inc.
Product ipTIME T5008
Versions Default: unaffected
  • affected from 0 to 15.26.8 (incl.)
Vendor EFM-Networks, Inc.
Product ipTIME AX2004M
Versions Default: unaffected
  • affected from 0 to 15.26.8 (incl.)
Vendor EFM-Networks, Inc.
Product ipTIME AX3000Q
Versions Default: unaffected
  • affected from 0 to 15.26.8 (incl.)
Vendor EFM-Networks, Inc.
Product ipTIME AX6000M
Versions Default: unaffected
  • affected from 0 to 15.26.8 (incl.)

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE

Impacts

  • CAPEC-115 Authentication Bypass