---
id: CVE-2026-8234
title: A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2
summary: >-
  A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This
  vulnerability affects the function formWifiBasicSet of the file
  /goform/WifiBasicSet. The manipulation of the argument security_5g leads to
  stack-based buffer …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-121
published: '2026-05-10'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8234'
references:
  - url: 'https://github.com/Kiciot/cve/issues/5'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/808865'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362454'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362454/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00805
epssPercentile: 0.5486
ingestedAt: '2026-07-24T07:21:21.395Z'
---

## Overview

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
