


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cg…
Published:
4 mei 2026 om 22:00:00
Alert date:
5 mei 2026 om 20:13:49
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A stack-based buffer overflow vulnerability (CVE-2026-7834) has been discovered in EFM ipTIME NAS1dual version 1.5.24. The vulnerability affects the get_csrf_whites function in the /cgi/advanced/misc_main.cgi file and can be exploited remotely. The exploit has been publicly disclosed and is available for use. The vendor was contacted about the disclosure but did not respond. This represents a high-risk vulnerability in IoT network attached storage devices that could allow remote attackers to execute arbitrary code through buffer overflow exploitation.
Technical details
Mitigation steps:
Affected products:
EFM ipTIME NAS1dual
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7834
https://github.com/glkfc/IoT-Vulnerability/blob/main/iptime/nas1dual/iptime2_en.md
https://vuldb.com/submit/807787
https://vuldb.com/vuln/361113
https://vuldb.com/vuln/361113/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
