CVE-2026-78168Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-24); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-24: 2Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-08-30: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-30: 108-2408-30
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure2
2026-08-301
PoC1
Full discourse3 posts
  • SecAlerts@SecAlertsCo
    PoC

    ⚠️ PoC exists for CVE-2026-78168 in EFM ipTIME T24000M. The httpcon_check_session_url function mishandles session validation, enabling unauthenticated network access with high impact. Affects firmware up to 14.20.0. #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-78168?utm_campaign=x https://t.co/CgGJu0TueO

    Post summary

    Proof of concept for CVE-2026-78168 shows unauthenticated network access via the httpcon_check_session_url function on ipTIME T24000M firmware up to 14.20.0; no indications of active exploitation, available patches, or false complaints.

    00000111
    884 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78168 Improper Authentication in EFM ipTIME T24000M Session Validation Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78168

    Post summary

    The post announces CVE-2026-78168, detailing an improper authentication flaw in the EFM ipTIME T24000M session validation handler, but offers no proof of concept, exploit code, active usage evidence, or patch information.

    00000109
    4.1K followersView on X
  • Can Turk@iamcanturk
    Disclosure

    CVE-2026-78168 (CVSS 10.0) - EFM ipTIME T24000M router'larda oturum doğrulama açığı. httpcon_check_session_url fonksiyonundaki zafiyet uzaktan kimlik doğrulama bypass'ına izin veriyor.

    Post summary

    The post announces a critical authentication bypass vulnerability (CVE-2026-78168) in EFM ipTIME T24000M routers that allows remote bypass of session authentication via the httpcon_check_session_url function.

    00000175
    592 followersView on X

Explore more