top of page
perceptive_background_267k.jpg

A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cg…

Published:

4 mei 2026 om 22:00:00

Alert date:

5 mei 2026 om 20:13:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

A stack-based buffer overflow vulnerability (CVE-2026-7834) has been discovered in EFM ipTIME NAS1dual version 1.5.24. The vulnerability affects the get_csrf_whites function in the /cgi/advanced/misc_main.cgi file and can be exploited remotely. The exploit has been publicly disclosed and is available for use. The vendor was contacted about the disclosure but did not respond. This represents a high-risk vulnerability in IoT network attached storage devices that could allow remote attackers to execute arbitrary code through buffer overflow exploitation.

Technical details

Mitigation steps:

Affected products:

EFM ipTIME NAS1dual

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page