<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-90847 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-90847/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 01:37:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-90847/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in EFM ipTIME C200E via Command Injection</title><link>https://feed.craftedsignal.io/briefs/2026-09-iptime-c200e-rce/</link><pubDate>Tue, 15 Sep 2026 01:37:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-iptime-c200e-rce/</guid><description>An unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.</description><content:encoded><![CDATA[<p>EFM ipTIME C200E firmware version 1.094 is vulnerable to an OS command injection flaw located within the iux_set.cgi file of the System Setup component. This vulnerability stems from improper input validation when handling requests sent to the CGI interface. An unauthenticated, remote attacker can exploit this weakness by crafting malicious HTTP requests to the target device. Successful exploitation allows for the execution of arbitrary commands with the privileges of the web service process, which typically runs with elevated permissions on embedded networking devices. Given the public disclosure of a functional exploit, organizations utilizing these devices face an immediate risk of compromise, including potential device hijacking, unauthorized data access, or integration into botnets.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-90847 grants an attacker remote code execution capabilities on the affected ipTIME C200E devices. This can lead to a total loss of confidentiality, integrity, and availability of the device, potentially facilitating lateral movement into the local network where the device is deployed. As the vulnerability is remotely exploitable without authentication, any internet-exposed device is at high risk of automated exploitation by threat actors scanning for vulnerable networking equipment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Identify and inventory all EFM ipTIME C200E devices deployed within the environment. If possible, restrict administrative access and the iux_set.cgi interface to trusted internal management subnets. Monitor web server logs for HTTP requests directed at iux_set.cgi containing shell metacharacters such as semicolon, pipe, or backticks that suggest command injection attempts. Contact the vendor for firmware updates addressing CVE-2026-90847.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>cve-2026-90847</category><category>networking</category><category>command-injection</category></item></channel></rss>