CVE-2026-19977Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 6 mentions (2026-08-17); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-08-17: 6Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-17: 2Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-17: 5Technical Details · 2026-08-19: 108-1708-19
Signal classification5 categories
Disclosure
342.9%
Exploit
114.3%
General
114.3%
PoC
114.3%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-176
Disclosure3Exploit1General1PoC1
2026-08-191
Patch1
Full discourse7 posts
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-19977 [HIGH PRIORITY] #EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authe... 🔗 https://exploitgrid.net/cve/CVE-2026-19977

    Post summary

    The post announces CVE‑2026‑19977 as high priority and links to an ExploitGrid page, suggesting a proof‑of‑concept is available, but it does not detail an active exploitation or provide patches.

    1000025
    33 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19977 CVE-2024-13784 CVE-2026-15623 CVE-2026-19959 CVE-2026-19961 ..🧵👇

    Post summary

    A brief daily digest that lists several CVE identifiers without additional context or detail.

    1000032
    33 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🔓 CVE-2026-19977: Critical 9.3 auth bypass in EFM ipTIME A3004T 14.19.0. httpcon_check_session_url fails session validation — no auth, network-accessible, full C/I/A impact. Update firmware now. #cybersecurity #vulnerabilities #ciso #msp #mssp https://secalerts.co/vulnerability/CVE-2026-19977?utm_campaign=x https://t.co/nA0bjDs8jK

    Post summary

    The tweet announces a high‑severity authentication bypass in ipTIME firmware and directly urges a firmware update, highlighting the need for a vendor patch.

    00000134
    880 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19977 A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Perform… https://www.cve.org/CVERecord?id=CVE-2026-19977 ----- Traducción: CVE-2026-19977 Se … https://infoflow.cloud`

    Post summary

    CVE‑2026‑19977 was identified in the EFM ipTIME A3004T firmware, affecting the httpcon_check_session_url component. No exploitable code, active attacks, or patch information are included.

    0000022
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19977 A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Perform… https://www.cve.org/CVERecord?id=CVE-2026-19977

    Post summary

    The text announces a newly detected vulnerability in the EFM ipTIME A3004T firmware, specifying the affected session validation function.

    00000778
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19977 Improper Authentication in EFM ipTIME A3004T Session Validation Due to Function Flaw https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19977

    Post summary

    A new CVE (CVE-2026-19977) affecting session validation in ipTIME A3004T routers via improper authentication is announced, with no PoC, exploit details, patch, or active exploitation reported.

    00000106
    4.1K followersView on X
  • ThreatAft@ThreatAft
    Exploit

    🚨 EFM ipTIME A3004T — CVSS 10.0 CRITICAL CVE-2026-19977: Unauthenticated session validation bypass → Full router admin access → Public exploit available → https://threataft.com/articles/efm-iptime-a3004t-cve-2026-19977 #cybersecurity #infosec #ipTIME #RouterSecurity #CVSS10 #NoPatch #ThreatIntel

    Post summary

    The tweet announces a critical CVE (CVE‑2026‑19977) affecting the EFM ipTIME A3004T router and claims a public exploit is available, but no patch or mitigation is discussed.

    0000058
    37 followersView on X

Explore more