
⚠️ PoC exists for CVE-2026-78168 in EFM ipTIME T24000M. The httpcon_check_session_url function mishandles session validation, enabling unauthenticated network access with high impact. Affects firmware up to 14.20.0. #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-78168?utm_campaign=x https://t.co/CgGJu0TueO
Post summary
Proof of concept for CVE-2026-78168 shows unauthenticated network access via the httpcon_check_session_url function on ipTIME T24000M firmware up to 14.20.0; no indications of active exploitation, available patches, or false complaints.


