CVE-2026-90847

CVE & Vulnerabilities · September 17, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly disclosed vulnerability, CVE-2026-90847, affects the EFM ipTIME C200E router running firmware 1.094, where a flaw in the System Setup component's iux_set.cgi script allows OS command injection. The bug can be triggered remotely, and proof-of-concept exploit details are already public, raising the risk of automated scanning and exploitation. Router owners should watch for a vendor patch and limit remote administrative access in the meantime.

// source: nvd.nist.gov ↗

Back to Blog