CVE-2026-2550 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: February 16, 2026
EFM iptime A6004MX - Unrestricted File Upload
Overview
EFM iptime A6004MX 14.18.2 contains an unrestricted file upload vulnerability caused by manipulation in commit_vpncli_file_upload function in /cgi/timepro.cgi, letting remote attackers upload arbitrary files, exploit requires no special privileges.
Severity & Score
Impact
Remote attackers can upload arbitrary files, potentially leading to remote code execution or system compromise.
Mitigation
Update to the latest version or apply vendor patches when available.
References
Social Media Activity(4 posts)
CVE-2026-2550 (CRITICAL): EFM iptime A6004MX (fw 14.18.2) allows unauthenticated uploads via /cgi/timepro.cgi — enabling full device compromise. No patch yet. Block access & monitor for malicious activity. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vuln #RouterSecurity #CVE2026
View original postCVE-2026-2550 (CRITICAL, CVSS 9.3) in EFM iptime A6004MX 14.18.2: Unrestricted remote file upload via /cgi/timepro.cgi. Exploit public, no vendor response. Isolate affected devices ASAP. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vulnerability #InfoSec #RouterSecurity
View original postCVE-2026-2550 (CRITICAL): EFM iptime A6004MX (fw 14.18.2) allows unauthenticated uploads via /cgi/timepro.cgi — enabling full device compromise. No patch yet. Block access & monitor for malicious activity. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vuln #RouterSecurity #CVE2026
View original postCVE-2026-2550 (CRITICAL, CVSS 9.3) in EFM iptime A6004MX 14.18.2: Unrestricted remote file upload via /cgi/timepro.cgi. Exploit public, no vendor response. Isolate affected devices ASAP. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vulnerability #InfoSec #RouterSecurity
View original postRelated Resources
Details
- CVE ID
- CVE-2026-2550
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- unrestricted_file_upload
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 4
CWE
- CWE-284
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H