CVE-2026-1742: EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commitvpnclifileupload of the file /cgi/timepro.cgi of the component VPN Service. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1742?
CVE-2026-1742 has a critical severity rating due to its potential for unrestricted file upload vulnerabilities.
How do I fix CVE-2026-1742?
To fix CVE-2026-1742, update your EFM ipTIME A8004T device to the latest firmware version that addresses this vulnerability.
What components are affected by CVE-2026-1742?
CVE-2026-1742 affects the commit_vpncli_file_upload function in the VPN Service of the EFM ipTIME A8004T router.
Can CVE-2026-1742 lead to remote code execution?
Yes, exploitation of CVE-2026-1742 can lead to remote code execution due to arbitrary file uploads.
Is there a workaround for CVE-2026-1742?
Until a patch is applied, disabling the VPN Service on affected EFM ipTIME A8004T devices can serve as a temporary workaround.