OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqDisclosure
CVE-2026-2550 is a newly disclosed vulnerability in EFM iptime A6004MX firmware 14.18.2 that allows unauthenticated file uploads, enabling full device takeover; no patch has been released yet.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPoC
The tweet announces a critical remote file upload vulnerability (CVE-2026-2550) with a publicly available exploit and no patch, urging isolation.
CVE@CVEnewDisclosure
The text announces a new CVE in the EFM iptime A6004MX device, noting the affected function and file, but offers no evidence of exploitation, PoC, or patch.
VulDB 🛡@vuldbGeneral
Severity increased for CVE‑2026‑2550 on EFM iptime A6004MX; no further exploit, patch, or technical details provided.
CRAC Learning - Tech@cracbotDisclosure
The text announces the discovery of CVE‑2026‑2550, a critical vulnerability in the commit_vpncli_file_upload function of the EFM iptime A6004MX firmware, with a CVSS score of 8.9 and no available patch or PoC yet.
The Hacker Wire@TheHackerWireDisclosure
A critical unrestricted upload vulnerability (CVE-2026-2550) was disclosed in the EFM iptime A6004MX firmware, enabling arbitrary file uploads via the commit_vpncli_file_upload function. No PoC or exploit details are provided.
CVEFind.com@CveFindComDisclosure
CVE-2026-2550 is a critical vulnerability in EFM iptime A6004MX 14.0.2 that allows unrestricted file uploads via /cgi/timepro.cgi, potentially enabling remote attacks; a public exploit is available but no active exploitation or patch is mentioned.