Vendor
The ipTIME A3004T router (firmware 14.19.0) is vulnerable to pre-authentication remote code execution via a flaw in the EAD service, allowing root command injection.