SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90847

CRITICAL · CVSS 9.1 EPSS 2.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The EFM ipTIME C200E version 1.094 is vulnerable due to a command injection flaw in the iux_set.cgi file within the System Setup component, allowing remote attackers to execute arbitrary OS commands. This critical vulnerability, with a CVSS score of 9.1, poses a significant risk to system integrity and confidentiality. Organizations using this device should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90847
Severity
CRITICAL
CVSS
9.1
EPSS
2.18%

Original NVD Description

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.