---
id: CVE-2026-19379
title: A vulnerability was determined in EFM ipTIME AX8004M 15.09.0
summary: >-
  A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the
  function popen of the file /cgi/d.cgi of the component CGI Endpoint. This
  manipulation of the argument fname causes os command injection. The attack can
  be ini…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19379'
references:
  - url: >-
      https://github.com/seting-and-break/vulnerability-reports/blob/main/ipTIME_AX8004M_Vulnerability_Report.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-19379'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/866635'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387272'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387272/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-10T06:39:06.398Z'
epss: 0.02657
epssPercentile: 0.85067
---

## Overview

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
