CVE-2026-24498
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through 15.26.8; ipTIME AX3000Q: through 15.26.8; ipTIME AX6000M: through 15.26.8.
Published:Feb 27, 2026
Last Modified:Apr 17, 2026
EPS:Feb 27, 2026
EPSS Score:0.00083
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Efm-networks
Product
Iptime Ax2004m
Efm-networks
Iptime Ax2004m
Vendor
Efm-networks
Product
Iptime Ax3000q
Efm-networks
Iptime Ax3000q
Vendor
Efm-networks
Product
Iptime Ax6000m
Efm-networks
Iptime Ax6000m
Vendor
Efm-networks
Product
Iptime T5008
Efm-networks
Iptime T5008
Vendor
Iptime
Product
Ax2004m
Iptime
Ax2004m
Vendor
Iptime
Product
Ax2004m Firmware
Iptime
Ax2004m Firmware
Vendor
Iptime
Product
Ax3000q
Iptime
Ax3000q
Vendor
Iptime
Product
Ax3000q Firmware
Iptime
Ax3000q Firmware
Vendor
Iptime
Product
Ax6000m
Iptime
Ax6000m
Vendor
Iptime
Product
Ax6000m Firmware
Iptime
Ax6000m Firmware
Vendor
Iptime
Product
T5008
Iptime
T5008
Vendor
Iptime
Product
T5008 Firmware
Iptime
T5008 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
