{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oefmiptime_c200e_firmware1.094/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:efm:iptime_c200e_firmware:1.094:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-90847"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ipTIME C200E (1.094)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","cve-2026-90847","networking","command-injection"],"_cs_type":"advisory","_cs_vendors":["EFM"],"content_html":"\u003cp\u003eEFM ipTIME C200E firmware version 1.094 is vulnerable to an OS command injection flaw located within the iux_set.cgi file of the System Setup component. This vulnerability stems from improper input validation when handling requests sent to the CGI interface. An unauthenticated, remote attacker can exploit this weakness by crafting malicious HTTP requests to the target device. Successful exploitation allows for the execution of arbitrary commands with the privileges of the web service process, which typically runs with elevated permissions on embedded networking devices. Given the public disclosure of a functional exploit, organizations utilizing these devices face an immediate risk of compromise, including potential device hijacking, unauthorized data access, or integration into botnets.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90847 grants an attacker remote code execution capabilities on the affected ipTIME C200E devices. This can lead to a total loss of confidentiality, integrity, and availability of the device, potentially facilitating lateral movement into the local network where the device is deployed. As the vulnerability is remotely exploitable without authentication, any internet-exposed device is at high risk of automated exploitation by threat actors scanning for vulnerable networking equipment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eIdentify and inventory all EFM ipTIME C200E devices deployed within the environment. If possible, restrict administrative access and the iux_set.cgi interface to trusted internal management subnets. Monitor web server logs for HTTP requests directed at iux_set.cgi containing shell metacharacters such as semicolon, pipe, or backticks that suggest command injection attempts. Contact the vendor for firmware updates addressing CVE-2026-90847.\u003c/p\u003e\n","date_modified":"2026-09-15T01:37:18Z","date_published":"2026-09-15T01:37:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-iptime-c200e-rce/","summary":"An unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.","title":"Remote Code Execution in EFM ipTIME C200E via Command Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-iptime-c200e-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:efm:iptime_c200e_firmware:1.094:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}