CVE-2026-7834
CRITICALEFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow
Title source: cnaDescription
A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References (4)
Core 4
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-361113 | EFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow
https://vuldb.com/vuln/361113
Signature, Permissions Required signature
permissions-required
VDB-361113 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/361113/cti
Third Party Advisory third-party-advisory
Submit #807787 | iptime nas1dual 1.5.24 Stack Overflow
https://vuldb.com/submit/807787
Scores
CVSS v3
9.8
EPSS
0.0063
EPSS Percentile
45.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-119
CWE-121
Status
published
Products (1)
EFM/ipTIME NAS1dual
1.5.24
Published
May 05, 2026
Tracked Since
May 05, 2026