CVE-2026-90847 PUBLISHED

EFM ipTIME C200E System Setup iux_set.cgi os command injection

Assigner: VulDB
Reserved: 14.09.2026 Published: 15.09.2026 Updated: 15.09.2026

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 9.4

Product Status

Vendor EFM
Product ipTIME C200E
Versions
  • Version 1.094 is affected

Credits

  • aissac (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE