Cyber & AI intelligence
Wasteland.
Briefs indexed2606
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-90847 2026-09-14

EFM ipTIME C200E Command Injection (CVE-2026-90847)

"A publicly disclosed OS command injection flaw in the System Setup interface of the EFM ipTIME C200E lets a remote, high-privileged attacker execute arbitrary commands with impact that breaks out of the vulnerable…"

A publicly disclosed OS command injection flaw in the System Setup interface of the EFM ipTIME C200E lets a remote, high-privileged attacker execute arbitrary commands with impact that breaks out of the vulnerable component's scope.

What Is It

CVE-2026-90847 is an OS command injection vulnerability (CWE-77, CWE-78) in EFM ipTIME C200E version 1.094. The affected code is an unknown function in the file iux_set.cgi, part of the product's System Setup component. Manipulating input to this function causes attacker-supplied operating system commands to be executed. The attack can be initiated remotely over the network.

The CVE record carries a CNA-supplied (VulDB) CVSS 3.1 base score of 9.1; CRITICAL (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). A secondary CVSS 4.0 score of 8.5 (HIGH) is also recorded, with exploit maturity rated Proof-of-Concept. NVD has not yet published its own analysis or severity assessment for this CVE, so these ratings reflect the CNA's scoring alone and may change.

Why It Matters

The vulnerability has been publicly disclosed, and the CNA notes the exploit may be used. Exploit maturity is rated only Proof-of-Concept, however, and the supplied data does not establish that reliable, weaponized attack tooling is circulating, nor is there any report of exploitation in the wild. Attack complexity is low, no user interaction is required, and the vector is remote. The CVSS 3.1 scope is marked Changed, indicating that successful command injection affects resources beyond the vulnerable component, consistent with the full confidentiality, integrity, and availability impact ratings.

The mitigating factor is that high privileges are required (PR:H), so an attacker needs existing administrative access. Where an administrative interface is reachable and protected only by default or reused credentials, that bar is lower than it appears.

What's Vulnerable

No other versions or products are identified in the supplied data. Note that the CPE is registered under the application (a) part rather than hardware (h), and the record does not otherwise classify the product's form factor or deployment role.

Patch Status

The supplied CVE record contains no vendor patch, fix version, or mitigation guidance. The record status is Received, meaning NVD analysis is not yet complete and details, including the CPE applicability data and severity ratings above, may change. This CVE does not appear in the CISA KEV catalog; there is no KEV entry confirming active exploitation and no federally mandated remediation deadline associated with it. Defenders should restrict administrative access to the web interface to trusted networks and monitor for vendor firmware updates.

Sources