Summary
CVE-2026-78167 is a critical improper authentication vulnerability in the EFM ipTIME T16000M router/switch, version 14.20.2. The flaw resides in the httpcon_check_session_url function of the device’s Session Validation Handler, allowing remote, unauthenticated attackers to bypass session validation. It carries the maximum CVSS v3.1 base score of 10.0, and a public proof-of-concept exploit is available.
Technical details
- Root cause: The
httpcon_check_session_urlfunction in the Session Validation Handler component fails to properly validate session state, allowing session/authentication checks to be bypassed. - Trigger conditions: An attacker sends a crafted HTTP request to the device’s management interface that manipulates the session validation logic; no valid credentials or prior session are required.
- Attack vector: Network-based, remotely exploitable with low attack complexity and no privileges or user interaction required.
- Impact: Full compromise of confidentiality, integrity, and availability of the device is possible, consistent with the CVSS impact metrics (C:H/I:H/A:H) and the scope-changed (S:C) vector, indicating potential impact beyond the vulnerable component itself.
Affected software
- EFM ipTIME T16000M, firmware version 14.20.2
Severity
- CVSS v3.1 Base Score: 10.0 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor patch has been confirmed as of this writing; the vendor was reportedly contacted about the issue but did not respond. Check EFM/ipTIME’s official support channels for a firmware update addressing this issue and apply it as soon as it is released.
- If no patch is available:
- Do not expose the ipTIME T16000M management/web interface to the internet; restrict access to trusted internal networks only.
- Place the device behind a VPN or firewall rule limiting inbound access to the administrative interface.
- Monitor device logs for unexpected session or authentication activity.
- Consider replacing or isolating the device if it cannot be taken offline from the public internet until a fix is available.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
ipTIME T16000M

