CVE-2026-90847
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the compone
CVSS
9.1
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 15 sept 2026 · Última mod.: 15 sept 2026 · CWE-77 · CWE-78
Sin historial EPSS suficiente todavía.
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
- drive.google.comhttps://drive.google.com/file/d/19WVo2tOImpmSEg3dFsmyB5Rw1aMQXyyd/view?usp=drive_link
- vuldb.comhttps://vuldb.com/cve/CVE-2026-90847
- vuldb.comhttps://vuldb.com/submit/925831
- vuldb.comhttps://vuldb.com/vuln/403400
- vuldb.comhttps://vuldb.com/vuln/403400/cti
- youtu.behttps://youtu.be/qdFGRSpCiY0
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-908807.4 ALT—
———A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.6hCVE-2026-908438.3 ALT—
———A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.10hCVE-2026-142776.3 MED—
———IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.14hCVE-2026-142766.3 MED—
———IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.14hCVE-2026-142756.3 MED—
———IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.14hCVE-2026-171337.8 ALT—
———IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.7h