CVE-2026-7834

CRITICAL

EFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-361113 | EFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow
https://vuldb.com/vuln/361113
Signature, Permissions Required signature permissions-required
VDB-361113 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/361113/cti
Third Party Advisory third-party-advisory
Submit #807787 | iptime nas1dual 1.5.24 Stack Overflow
https://vuldb.com/submit/807787

Scores

CVSS v3 9.8
EPSS 0.0063
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-119 CWE-121
Status published
Products (1)
EFM/ipTIME NAS1dual 1.5.24
Published May 05, 2026
Tracked Since May 05, 2026