CVE-2026-78168: EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication

Published Aug 24, 2026
·
Updated

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpconchecksessionurl of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
ipTIME (EFM) EFM ipTIME T24000M<=14.20.0

Event History

Aug 24, 2026
CVE Published
via MITRE·01:30 AM
Data Sourced
via MITRE·01:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

EFM ipTIME T24000M devices running version 14.20.0 or earlier are affected. The issue is remotely exploitable, so any reachable affected device should be considered exposed.

2

Does exploitation require credentials or user interaction?

No. The vulnerability is rated with no required privileges and no user interaction, with low attack complexity.

3

Is exploit code available?

Yes. The exploit has been publicly disclosed and may be used. The vendor was contacted but did not provide a response.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203