← All CVEs

CVE-2025-55423

critical · 9.8

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.

9.8
CVSS
3.8%
EPSS (exploit prob.)
90th
EPSS percentile
2026-01-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
iptimen104s-r1_firmware>= 9.90.8, <= 10.02.2
iptimen104s-r1all versions
iptimen104v_firmware>= 9.90.8, <= 10.06.8
iptimen104vall versions
iptimen1e_firmware>= 9.90.8, <= 10.06.8
iptimen1eall versions
iptimen1plus_firmware>= 9.90.8, <= 10.06.8
iptimen1plusall versions
iptimen1plus-i_firmware>= 9.99.6, <= 10.06.8
iptimen1plus-iall versions
iptimen1v_firmware>= 11.01.2, <= 12.07.6
iptimen1vall versions
iptimen2e_firmware>= 9.90.8, <= 10.06.8
iptimen2eall versions
iptimen2eplus_firmware>= 9.90.8, <= 10.06.8
iptimen2eplusall versions
iptimen2plus_firmware>= 9.90.8, <= 10.06.8
iptimen2plusall versions
iptimen2plus-i_firmware>= 9.99.6, <= 10.06.8
iptimen2plus-iall versions
iptimen2v_firmware>= 10.09.2, <= 12.16.8
iptimen2vall versions
iptimen2vs_firmware12.16.8
iptimen2vsall versions
iptimen3_firmware>= 9.93.2, <= 10.06.8
iptimen3all versions
iptimen3-i_firmware>= 9.99.6, <= 10.06.8
iptimen3-iall versions
iptimen5_firmware>= 9.90.8, <= 10.06.8
iptimen5all versions
iptimen5-i_firmware>= 9.99.6, <= 10.06.8
iptimen5-iall versions
iptimen6_firmware>= 9.96.8, <= 10.06.8
iptimen6all versions
iptimen600_firmware>= 10.00.8, <= 12.16.2
iptimen600all versions
iptimen6004r_firmware>= 9.90.8, <= 10.02.2
iptimen6004rall versions
iptimen602e_firmware>= 11.96.6, <= 12.16.8
iptimen602eall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-55423