A new entry for the ipTIME AX8004M describes a command injection that could lead to remote command execution. The report concerns firmware version 15.09.0 and is linked to CVE-2026-19379, which was published on August 10, 2026.
According to the CVE Feed, the issue is located in the CGI endpoint /cgi/d.cgi and the popen. The fname can reportedly be used to inject commands into the operating system, while the database does not yet show a CVSS score from NVD.
See also: MSI Radix AXE6600: Critical vulnerabilities allow root commands
The vulnerability in ipTIME AX8004M
The technical description attributes the vulnerability to inadequate checking of the value that reaches popen. When an application passes untrusted data to a function that starts processes, special symbols and additional arguments can change the meaning of the command. On a router, the effect is particularly serious because the CGI environment has access to network and management functions.
The listing describes the attack as remote and states that an exploit has been made public that could be exploited. However, it does not document active exploitation on real networks, nor does it publicly provide a complete attack process. This distinction is critical: the existence of an exploit increases the need for awareness, but does not in itself equate to a confirmed campaign.
The issue specifically concerns ipTIME AX8004M 15.09.0. The administrator should not assume that every version of the model is automatically vulnerable or that installing a newer version will necessarily fix the specific CVE without confirmation. The firmware version, dashboard report, and active services should be checked separately.

What does CVE-2026-19379 mean for a router?
A router sits at the boundary between the local network and the internet. If a vulnerable CGI endpoint is accessible from an untrusted network, an attacker can attempt to modify parameters, execute commands, and use the device as a monitoring point or as a base for further actions. The actual impact depends on the process permissions and access settings.
The history of vulnerabilities in ipTIME devices shows why caution is needed in Internet-exposed features. In a previous investigation into the Wavlink WL-NU516U1, the SecNews technical team noted that remote management and auxiliary endpoints expand the attack surface on routers and access points.
NVD has not yet completed a public description, affected configurations, or metrics for CVE-2026-19379. Therefore, information such as severity, authentication requirements, and privacy impact should be treated as unavailable until the listing is updated or a technical bulletin is published by the vendor .
For the ipTIME AX8004M, the check should not be limited to the version displayed on the login page. An inventory of active services, port forwarding rules, and administrative accounts is needed to determine if the endpoint is actually accessible and what permissions a potential process would have.
If the router is operating in a small business or in an infrastructure with cameras and storage devices, isolating management from the internet immediately reduces the risk. Changing passwords, disabling unnecessary services, and monitoring connections should be done before any reset.
See also: TRENDnet TEW-821DAP: New OS command injection CVEs in router
Update and temporary measures for ipTIME AX8004M
EFM has published a firmware page that includes a download for version 15.35.2 for the ipTIME AX8004M. The release describes bug fixes and stability improvements, but does not explicitly mention that it fixes CVE-2026-19379. Administrators should check the release notes and confirm with official support which version includes the relevant fix.
Until there is a clear answer, it is recommended to upgrade to the latest supported version only from the official EFM firmware page, after backing up the configuration. In the meantime, disable remote management from the internet, limit the management environment to trusted addresses, and check the logs for unknown connections or processes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also check if the CGI endpoint is accessible from WAN and if the device is using default or reused credentials. If there are signs of a breach, isolate the router, keep a copy of the logs and only restore the device with a controlled process. The SecNews technical team will monitor the CVE registration and any EFM announcement for definitive confirmation.

See also: D-Link DWR-M961: Vulnerabilities that allow root commands
