{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/iptime-ax8004m-15.09.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19379"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ipTIME AX8004M (15.09.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["EFM"],"content_html":"\u003cp\u003eThe EFM ipTIME AX8004M router (firmware version 15.09.0) contains a critical remote command injection vulnerability, tracked as CVE-2026-19379. The flaw originates in the handling of the 'fname' argument within the 'popen' function of the '/cgi/d.cgi' component. Because this endpoint fails to properly sanitize user-supplied input before passing it to the underlying system shell, an unauthenticated remote attacker can inject and execute arbitrary commands with the privileges of the web server process. This vulnerability is significant due to the device's role as a network gateway, potentially providing attackers with a foothold to intercept traffic, perform lateral movement, or conduct further exploitation within the internal network. Disclosure of this vulnerability has occurred publicly without a corresponding vendor patch, leaving deployed devices exposed to potential exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify ipTIME AX8004M devices reachable via the internet.\u003c/li\u003e\n\u003cli\u003eAttacker probes the target for the presence of the vulnerable '/cgi/d.cgi' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker constructs an HTTP GET or POST request targeting the 'fname' parameter.\u003c/li\u003e\n\u003cli\u003eAttacker inserts shell metacharacters (e.g., semicolon, pipe, backticks) into the 'fname' argument string.\u003c/li\u003e\n\u003cli\u003eThe web server process passes the unsanitized 'fname' string to the 'popen' function.\u003c/li\u003e\n\u003cli\u003eThe underlying system shell interprets the injected metacharacters and executes the attacker's payload.\u003c/li\u003e\n\u003cli\u003eAttacker gains remote command execution on the router, establishing persistence or exfiltrating data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote compromise of the ipTIME AX8004M router. Impacted organizations and residential users face the risk of total device takeover, which can facilitate man-in-the-middle attacks, credential theft, or the use of the router as a node in a botnet. As of the current disclosure, no vendor-provided patch exists, making immediate network-level isolation or firewalling of management interfaces the only viable mitigation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor ingress traffic to internal networks for HTTP requests directed toward the '/cgi/d.cgi' URI stem.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall rules to prevent remote access to router management interfaces from untrusted or public IP addresses.\u003c/li\u003e\n\u003cli\u003eAudit logs for suspicious command execution patterns originating from web service processes on network appliances.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T01:50:07Z","date_published":"2026-08-10T01:50:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-iptime-rce/","summary":"The EFM ipTIME AX8004M router version 15.09.0 is vulnerable to remote command injection via the /cgi/d.cgi CGI endpoint, allowing unauthenticated attackers to execute arbitrary system commands.","title":"Remote Command Injection in EFM ipTIME AX8004M","url":"https://feed.craftedsignal.io/briefs/2026-08-iptime-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - IpTIME AX8004M (15.09.0)","version":"https://jsonfeed.org/version/1.1"}