Product
The EFM ipTIME AX8004M router version 15.09.0 is vulnerable to remote command injection via the /cgi/d.cgi CGI endpoint, allowing unauthenticated attackers to execute arbitrary system commands.