CVE-2026-78167PoC

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-24); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-08-24: 3Mentions · 2026-08-30: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-30: 1Active Exploitation · 2026-09-04: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-30: 1Technical Details · 2026-09-04: 108-2408-3009-04
Signal classification4 categories
PoC
240.0%
Disclosure
120.0%
General
120.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-243
Disclosure1General1PoC1
2026-08-301
PoC1
2026-09-041
Active Exploitation1
Full discourse5 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-78167 CVE-2026-78155 CVE-2026-78211 CVE-2026-78169 CVE-2026-5388 ..🧵👇

    Post summary

    The tweet lists five CVE identifiers but contains no further insight into the vulnerabilities, exploits, or mitigations.

    1001038
    38 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚡ Consumer Router Flaws: Exploits in the Wild, No Fixes SOHO router vulnerabilities continue to pile up with no remediation in sight. CVE-2026-78167 (CVSS 10.0) targets EFM ipTIME T16000M 14.20.2, exploiting the…

    Post summary

    CVE‑2026‑78167 is being exploited in the wild against ipTIME T16000M routers, with no patch available—posing a critical, unmitigated risk.

    1000024
    85 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-78167 [HIGH PRIORITY] #EFM ipTIME T16000M Session Validation httpcon_check_session_url improper auth... 🔗 https://exploitgrid.net/cve/CVE-2026-78167

    Post summary

    The tweet links to an exploitgrid page for CVE-2026-78167, signaling that a proof‑of‑concept exists for an authentication bypass in the ipTIME T16000M; no evidence of active exploitation or patching is provided.

    1000030
    38 followersView on X
  • SecAlerts@SecAlertsCo
    PoC

    PoC exists 🔓 CVE-2026-78167: EFM ipTIME T16000M 14.20.2 has a critical (9.3) auth bypass in httpcon_check_session_url — no creds, no interaction, full C/I/A impact. Check your network gear. #cybersecurity #vulnerabilities #ciso #mssp https://secalerts.co/vulnerability/CVE-2026-78167?utm_campaign=x https://t.co/JLGivxu476

    Post summary

    A proof‑of‑concept demonstrates a critical authentication bypass in httpcon_check_session_url, with full confidentiality, integrity, and availability impact, but no exploit tools or patch details are provided.

    00000172
    884 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78167 Improper Authentication in EFM ipTIME T16000M Session Validation ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78167 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE‑2026‑78167 as an improper authentication flaw in EFM ipTIME T16000M, providing a link to a vulnerability details page without mentioning exploits, patches, or active exploitation.

    00000109
    4.1K followersView on X

Explore more