9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Unrestricted file upload vulnerability in the commit_vpncli_file_upload function of the /cgi/timepro.cgi file
Basic Information
ID
CVE-2026-2550
Source
VulDB
Published
Feb 16, 2026 at 10:02
Affected Product
Vendor
EFM
Product
iptime A6004MX
Version
14.18.2
Affected Versions
EFM iptime A6004MX 14.18.2
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
EFM
Product
iptime A6004MX
Version
14.18.2