CVE-2025-55423
critical · 9.8A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
9.8
CVSS
3.8%
EPSS (exploit prob.)
90th
EPSS percentile
2026-01-20
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| iptime | n104s-r1_firmware | >= 9.90.8, <= 10.02.2 |
| iptime | n104s-r1 | all versions |
| iptime | n104v_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n104v | all versions |
| iptime | n1e_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n1e | all versions |
| iptime | n1plus_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n1plus | all versions |
| iptime | n1plus-i_firmware | >= 9.99.6, <= 10.06.8 |
| iptime | n1plus-i | all versions |
| iptime | n1v_firmware | >= 11.01.2, <= 12.07.6 |
| iptime | n1v | all versions |
| iptime | n2e_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n2e | all versions |
| iptime | n2eplus_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n2eplus | all versions |
| iptime | n2plus_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n2plus | all versions |
| iptime | n2plus-i_firmware | >= 9.99.6, <= 10.06.8 |
| iptime | n2plus-i | all versions |
| iptime | n2v_firmware | >= 10.09.2, <= 12.16.8 |
| iptime | n2v | all versions |
| iptime | n2vs_firmware | 12.16.8 |
| iptime | n2vs | all versions |
| iptime | n3_firmware | >= 9.93.2, <= 10.06.8 |
| iptime | n3 | all versions |
| iptime | n3-i_firmware | >= 9.99.6, <= 10.06.8 |
| iptime | n3-i | all versions |
| iptime | n5_firmware | >= 9.90.8, <= 10.06.8 |
| iptime | n5 | all versions |
| iptime | n5-i_firmware | >= 9.99.6, <= 10.06.8 |
| iptime | n5-i | all versions |
| iptime | n6_firmware | >= 9.96.8, <= 10.06.8 |
| iptime | n6 | all versions |
| iptime | n600_firmware | >= 10.00.8, <= 12.16.2 |
| iptime | n600 | all versions |
| iptime | n6004r_firmware | >= 9.90.8, <= 10.02.2 |
| iptime | n6004r | all versions |
| iptime | n602e_firmware | >= 11.96.6, <= 12.16.8 |
| iptime | n602e | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://docs.google.com/spreadsheets/d/1kryOFltCmnPJvDTpIrudgryt79uI4PWchuQ8-Gak24c/edit?usp=sharing
- https://github.com/0x0xxxx/CVE/blob/main/CVE-2025-55423/README.md
- https://github.com/0x0xxxx/CVE/blob/main/CVE-2025-55423/assets/affected_products_cve_format.json
- https://iptime.com/iptime/?pageid=4&page_id=126&dfsid=3&dftid=583&uid=25203&mod=document
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-55423