← Browse

CVE-2026-90847

Medium

Elevated severity or exploit probability.

CVSS base
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
3.4%
88.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-77
Published 2026-09-15 · modified 2026-09-15

Description

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

References

Official: NVD · CVE.org