CVE-2026-2550Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-02-16); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-02-15: 1Mentions · 2026-02-16: 5Mentions · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-16: 2Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 5Technical Details · 2026-02-20: 102-1502-1602-20
Signal classification3 categories
Disclosure
571.4%
General
114.3%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-151
General1
2026-02-165
Disclosure4PoC1
2026-02-201
Disclosure1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2550 A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in un… https://www.cve.org/CVERecord?id=CVE-2026-2550

    Post summary

    The text announces a new CVE in the EFM iptime A6004MX device, noting the affected function and file, but offers no evidence of exploitation, PoC, or patch.

    00010175
    56.4K followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting EFM iptime A6004MX (CVE-2026-2550) https://vuldb.com/?id.346159

    Post summary

    Severity increased for CVE‑2026‑2550 on EFM iptime A6004MX; no further exploit, patch, or technical details provided.

    0000176
    2.1K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2550 (CVSS:8.9, CRITICAL) is Awaiting Analysis. A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file ..https://nvd.nist.gov/vuln/detail/CVE-2026-2550 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces the discovery of CVE‑2026‑2550, a critical vulnerability in the commit_vpncli_file_upload function of the EFM iptime A6004MX firmware, with a CVSS score of 8.9 and no available patch or PoC yet.

    0000032
    171 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2550 - Critical A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. T... https://www.thehackerwire.com/vulnerability/CVE-2026-2550/ https://t.co/WyalVixlBJ

    Post summary

    A critical unrestricted upload vulnerability (CVE-2026-2550) was disclosed in the EFM iptime A6004MX firmware, enabling arbitrary file uploads via the commit_vpncli_file_upload function. No PoC or exploit details are provided.

    0000040
    112 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2550: CRITICAL] Critical cyber security alert: Vulnerability in EFM iptime A6004MX 14.18.2 allows unrestricted file uploads via /cgi/timepro.cgi, making remote attacks possible. Public exploit availa...#cve,CVE-2026-2550,#cybersecurity https://cvefind.com/CVE-2026-2550

    Post summary

    CVE-2026-2550 is a critical vulnerability in EFM iptime A6004MX 14.0.2 that allows unrestricted file uploads via /cgi/timepro.cgi, potentially enabling remote attacks; a public exploit is available but no active exploitation or patch is mentioned.

    0000057
    580 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 Critical vuln in EFM iptime A6004MX (fw 14.18.2): CVE-2026-2550 allows unauthenticated file uploads — full device takeover possible! No patch yet. Restrict access & monitor now. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffS... https://t.co/XcCo7EXfv1

    Post summary

    CVE-2026-2550 is a newly disclosed vulnerability in EFM iptime A6004MX firmware 14.18.2 that allows unauthenticated file uploads, enabling full device takeover; no patch has been released yet.

    0000069
    265 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    PoC

    🚨 CRITICAL: CVE-2026-2550 hits EFM iptime A6004MX (14.18.2) — unrestricted remote file upload risk! Exploit public, vendor silent. Patch unavailable — isolate now! https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vulnerabilit... https://t.co/NX3wWyU0NS

    Post summary

    The tweet announces a critical remote file upload vulnerability (CVE-2026-2550) with a publicly available exploit and no patch, urging isolation.

    0000041
    265 followersView on X

Explore more