CVE-2026-24498: Infoleak
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through 15.26.8; ipTIME AX3000Q: through 15.26.8; ipTIME AX6000M: through 15.26.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24498?
CVE-2026-24498 is classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-24498?
To fix CVE-2026-24498, users should update their affected IpTIME devices to the latest firmware version provided by EFM-Networks.
Which devices are impacted by CVE-2026-24498?
CVE-2026-24498 affects the IpTIME T5008, AX2004M, AX3000Q, and AX6000M models running firmware versions up to 15.26.8.
What type of vulnerability is CVE-2026-24498?
CVE-2026-24498 is categorized as an exposure of sensitive information to an unauthorized actor due to authentication bypass.
Can CVE-2026-24498 lead to further exploitation?
Yes, CVE-2026-24498 could potentially lead to further exploitation if an attacker gains unauthorized access to the affected devices.