CVE-2026-24498

HIGH

IpTIME T5008/AX2004M/AX3000Q/AX6000M - Info Disclosure

Title source: llm
STIX 2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through 15.26.8; ipTIME AX3000Q: through 15.26.8; ipTIME AX6000M: through 15.26.8.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (8)
EFM-Networks, Inc./ipTIME AX2004M < 15.26.8
EFM-Networks, Inc./ipTIME AX3000Q < 15.26.8
EFM-Networks, Inc./ipTIME AX6000M < 15.26.8
EFM-Networks, Inc./ipTIME T5008 < 15.26.8
iptime/ax2004m_firmware < 15.27.2
iptime/ax3000q_firmware < 15.27.2
iptime/ax6000m_firmware < 15.27.2
iptime/t5008_firmware < 15.27.2
Published Feb 27, 2026
Tracked Since Feb 27, 2026