Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-55423


A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.


Security Impact Summary

This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 326 products from iptime, from iptime, from iptime and 323 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2026, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2026-01-20T18:16:04.810

Last Modified

2026-01-30T20:07:11.633

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System iptime n104s-r1_firmware ≤ 10.02.2 Yes
Hardware iptime n104s-r1 - No
Operating System iptime n104v_firmware ≤ 10.06.8 Yes
Hardware iptime n104v - No
Operating System iptime n1e_firmware ≤ 10.06.8 Yes
Hardware iptime n1e - No
Operating System iptime n1plus_firmware ≤ 10.06.8 Yes
Hardware iptime n1plus - No
Operating System iptime n1plus-i_firmware ≤ 10.06.8 Yes
Hardware iptime n1plus-i - No
Operating System iptime n1v_firmware ≤ 12.07.6 Yes
Hardware iptime n1v - No
Operating System iptime n2e_firmware ≤ 10.06.8 Yes
Hardware iptime n2e - No
Operating System iptime n2eplus_firmware ≤ 10.06.8 Yes
Hardware iptime n2eplus - No
Operating System iptime n2plus_firmware ≤ 10.06.8 Yes
Hardware iptime n2plus - No
Operating System iptime n2plus-i_firmware ≤ 10.06.8 Yes
Hardware iptime n2plus-i - No
Operating System iptime n2v_firmware ≤ 12.16.8 Yes
Hardware iptime n2v - No
Operating System iptime n2vs_firmware 12.16.8 Yes
Hardware iptime n2vs - No
Operating System iptime n3_firmware ≤ 10.06.8 Yes
Hardware iptime n3 - No
Operating System iptime n3-i_firmware ≤ 10.06.8 Yes
Hardware iptime n3-i - No
Operating System iptime n5_firmware ≤ 10.06.8 Yes
Hardware iptime n5 - No
Operating System iptime n5-i_firmware ≤ 10.06.8 Yes
Hardware iptime n5-i - No
Operating System iptime n6_firmware ≤ 10.06.8 Yes
Hardware iptime n6 - No
Operating System iptime n600_firmware ≤ 12.16.2 Yes
Hardware iptime n600 - No
Operating System iptime n6004r_firmware ≤ 10.02.2 Yes
Hardware iptime n6004r - No
Operating System iptime n602e_firmware ≤ 12.16.8 Yes
Hardware iptime n602e - No
Operating System iptime n602eplus_firmware ≤ 12.16.2 Yes
Hardware iptime n602eplus - No
Operating System iptime n602se_firmware ≤ 14.19.4 Yes
Hardware iptime n602se - No
Operating System iptime n604_black_firmware ≤ 12.16.2 Yes
Hardware iptime n604_black - No
Operating System iptime n604a_firmware ≤ 10.06.8 Yes
Hardware iptime n604a - No
Operating System iptime n604e_firmware ≤ 14.19.4 Yes
Hardware iptime n604e - No
Operating System iptime n604eplus_firmware ≤ 14.19.4 Yes
Hardware iptime n604eplus - No
Operating System iptime n604plus_firmware ≤ 12.15.2 Yes
Hardware iptime n604plus - No
Operating System iptime n604plus-i_firmware ≤ 12.14.6 Yes
Hardware iptime n604plus-i - No
Operating System iptime n604r_firmware ≤ 10.06.8 Yes
Hardware iptime n604r - No
Operating System iptime n604rplus_firmware ≤ 10.06.8 Yes
Hardware iptime n604rplus - No
Operating System iptime n604rplus-i_firmware ≤ 10.06.8 Yes
Hardware iptime n604rplus-i - No
Operating System iptime n604s_firmware ≤ 10.06.8 Yes
Hardware iptime n604s - No
Operating System iptime n604se_firmware ≤ 14.19.4 Yes
Hardware iptime n604se - No
Operating System iptime n604t_firmware ≤ 10.03.2 Yes
Hardware iptime n604t - No
Operating System iptime n604tplus_firmware ≤ 10.03.2 Yes
Hardware iptime n604tplus - No
Operating System iptime n604v_firmware ≤ 10.06.8 Yes
Hardware iptime n604v - No
Operating System iptime n604vplus_firmware ≤ 10.06.8 Yes
Hardware iptime n604vplus - No
Operating System iptime n7004ns_firmware 9.91.2 Yes
Hardware iptime n7004ns - No
Operating System iptime n702bcm_firmware ≤ 12.16.2 Yes
Hardware iptime n702bcm - No
Operating System iptime n702e_firmware ≤ 12.16.2 Yes
Hardware iptime n702e - No
Operating System iptime ax11000_firmware ≤ 14.19.4 Yes
Hardware iptime ax11000 - No
Operating System iptime ax2002mesh_firmware ≤ 14.19.4 Yes
Hardware iptime ax2002mesh - No
Operating System iptime ax2004_firmware ≤ 14.19.4 Yes
Hardware iptime ax2004 - No
Operating System iptime ax2004bcm_firmware ≤ 14.19.4 Yes
Hardware iptime ax2004bcm - No
Operating System iptime ax2004m_firmware ≤ 14.19.4 Yes
Hardware iptime ax2004m - No
Operating System iptime ax3004bcm_firmware ≤ 14.19.4 Yes
Hardware iptime ax3004bcm - No
Operating System iptime ax3004itl_firmware ≤ 14.19.4 Yes
Hardware iptime ax3004itl - No
Operating System iptime ax8004bcm_firmware ≤ 14.19.4 Yes
Hardware iptime ax8004bcm - No
Operating System iptime ax8004m_firmware ≤ 14.19.4 Yes
Hardware iptime ax8004m - No
Operating System iptime ax8008m_firmware ≤ 14.19.4 Yes
Hardware iptime ax8008m - No
Operating System iptime a1_firmware ≤ 10.07.4 Yes
Hardware iptime a1 - No
Operating System iptime a1004_firmware ≤ 12.16.2 Yes
Hardware iptime a1004 - No
Operating System iptime a1004ns_firmware ≤ 12.16.2 Yes
Hardware iptime a1004ns - No
Operating System iptime a1004v_firmware ≤ 12.16.2 Yes
Hardware iptime a1004v - No
Operating System iptime a104_firmware ≤ 10.03.8 Yes
Hardware iptime a104 - No
Operating System iptime a104ns_firmware ≤ 12.16.2 Yes
Hardware iptime a104ns - No
Operating System iptime a104r_firmware ≤ 10.07.4 Yes
Operating System iptime a104r_firmware - Yes
Hardware iptime a104r - No
Operating System iptime a2003mu_firmware ≤ 12.16.2 Yes
Hardware iptime a2003mu - No
Operating System iptime a2003ns-mu_firmware ≤ 12.16.2 Yes
Hardware iptime a2003ns-mu - No
Operating System iptime a2004_firmware ≤ 10.07.4 Yes
Hardware iptime a2004 - No
Operating System iptime a2004mu_firmware ≤ 12.17.0 Yes
Hardware iptime a2004mu - No
Operating System iptime a2004ns_firmware ≤ 11.00.4 Yes
Hardware iptime a2004ns - No
Operating System iptime a2004ns-mu_firmware ≤ 12.17.0 Yes
Hardware iptime a2004ns-mu - No
Operating System iptime a2004ns-r_firmware ≤ 11.00.4 Yes
Hardware iptime a2004ns-r - No
Operating System iptime a2004nsplus_firmware ≤ 11.00.4 Yes
Hardware iptime a2004nsplus - No
Operating System iptime a2004plus_firmware ≤ 10.07.4 Yes
Hardware iptime a2004plus - No
Operating System iptime a2004r_firmware ≤ 10.07.4 Yes
Hardware iptime a2004r - No
Operating System iptime a2004se_firmware ≤ 14.19.4 Yes
Hardware iptime a2004se - No
Operating System iptime a2008_firmware ≤ 10.07.4 Yes
Hardware iptime a2008 - No
Operating System iptime a3_firmware ≤ 10.07.2 Yes
Hardware iptime a3 - No
Operating System iptime a3002mesh_firmware ≤ 14.19.4 Yes
Hardware iptime a3002mesh - No
Operating System iptime a3003ns_firmware ≤ 11.00.4 Yes
Hardware iptime a3003ns - No
Operating System iptime a3004_firmware ≤ 10.08.2 Yes
Hardware iptime a3004 - No
Operating System iptime a3004-dual_firmware ≤ 10.07.2 Yes
Hardware iptime a3004-dual - No
Operating System iptime a3004m_firmware ≤ 14.19.4 Yes
Hardware iptime a3004m - No
Operating System iptime a3004ns_firmware ≤ 10.09.4 Yes
Hardware iptime a3004ns - No
Operating System iptime a3004ns-bcm_firmware ≤ 11.00.4 Yes
Hardware iptime a3004ns-bcm - No
Operating System iptime a3004ns-dual_firmware ≤ 12.09.4 Yes
Hardware iptime a3004ns-dual - No
Operating System iptime a3004ns-m_firmware ≤ 14.19.4 Yes
Hardware iptime a3004ns-m - No
Operating System iptime a3004t_firmware ≤ 14.19.4 Yes
Hardware iptime a3004t - No
Operating System iptime a3004tw_firmware ≤ 14.19.4 Yes
Hardware iptime a3004tw - No
Operating System iptime a3008-mu_firmware ≤ 14.19.4 Yes
Hardware iptime a3008-mu - No
Operating System iptime a304_firmware ≤ 10.07.4 Yes
Hardware iptime a304 - No
Operating System iptime a5004ns_firmware ≤ 11.00.4 Yes
Hardware iptime a5004ns - No
Operating System iptime a5004ns-m_firmware ≤ 14.19.4 Yes
Hardware iptime a5004ns-m - No
Operating System iptime a6004mx_firmware ≤ 14.19.4 Yes
Hardware iptime a6004mx - No
Operating System iptime a6004ns_firmware ≤ 11.00.4 Yes
Hardware iptime a6004ns - No
Operating System iptime a6004ns-m_firmware ≤ 14.19.4 Yes
Hardware iptime a6004ns-m - No
Operating System iptime a604_firmware ≤ 12.06.6 Yes
Hardware iptime a604 - No
Operating System iptime a604-v3_firmware ≤ 10.07.2 Yes
Hardware iptime a604-v3 - No
Operating System iptime a604-v5_firmware ≤ 12.16.2 Yes
Hardware iptime a604-v5 - No
Operating System iptime a604g-mu_firmware ≤ 12.16.2 Yes
Hardware iptime a604g-mu - No
Operating System iptime a604g-skylife_firmware ≤ 12.12.4 Yes
Hardware iptime a604g-skylife - No
Operating System iptime a604m_firmware ≤ 10.07.2 Yes
Hardware iptime a604m - No
Operating System iptime a604mu_firmware ≤ 12.16.2 Yes
Hardware iptime a604mu - No
Operating System iptime a604r_firmware ≤ 12.16.2 Yes
Hardware iptime a604r - No
Operating System iptime a604se_firmware ≤ 14.19.4 Yes
Hardware iptime a604se - No
Operating System iptime a604v_firmware ≤ 10.07.4 Yes
Hardware iptime a604v - No
Operating System iptime a6ns-m_firmware ≤ 14.19.4 Yes
Hardware iptime a6ns-m - No
Operating System iptime a7004m_firmware ≤ 14.19.4 Yes
Hardware iptime a7004m - No
Operating System iptime a704ns-bcm_firmware ≤ 11.00.4 Yes
Hardware iptime a704ns-bcm - No
Operating System iptime a7ns_firmware ≤ 11.00.4 Yes
Hardware iptime a7ns - No
Operating System iptime a8004bcm_firmware ≤ 12.16.2 Yes
Hardware iptime a8004bcm - No
Operating System iptime a8004itl_firmware ≤ 14.19.4 Yes
Hardware iptime a8004itl - No
Operating System iptime a8004ns-m_firmware ≤ 14.19.4 Yes
Hardware iptime a8004ns-m - No
Operating System iptime a8004t_firmware ≤ 14.19.4 Yes
Hardware iptime a8004t - No
Operating System iptime a8004t-xr_firmware ≤ 14.19.4 Yes
Hardware iptime a8004t-xr - No
Operating System iptime a804ns-mu_firmware ≤ 12.10.2 Yes
Hardware iptime a804ns-mu - No
Operating System iptime a8ns-m_firmware ≤ 14.19.4 Yes
Hardware iptime a8ns-m - No
Operating System iptime a9004m_firmware ≤ 14.19.4 Yes
Hardware iptime a9004m - No
Operating System iptime a9004m-x2_firmware ≤ 14.19.4 Yes
Hardware iptime a9004m-x2 - No
Operating System iptime ew302n_firmware ≤ 12.16.2 Yes
Hardware iptime ew302n - No
Operating System iptime n102e_firmware ≤ 12.15.2 Yes
Hardware iptime n102e - No
Operating System iptime n102eplus_firmware ≤ 12.15.2 Yes
Hardware iptime n102eplus - No
Operating System iptime n102i_firmware ≤ 12.15.2 Yes
Hardware iptime n102i - No
Operating System iptime n102iplus_firmware ≤ 12.15.2 Yes
Hardware iptime n102iplus - No
Operating System iptime n104_black_firmware ≤ 10.06.8 Yes
Hardware iptime n104_black - No
Operating System iptime n104e_firmware ≤ 12.15.2 Yes
Hardware iptime n104e - No
Operating System iptime n104eplus_firmware ≤ 12.15.2 Yes
Hardware iptime n104eplus - No
Operating System iptime n104k_firmware ≤ 10.06.8 Yes
Hardware iptime n104k - No
Operating System iptime n104plus_firmware ≤ 10.06.8 Yes
Hardware iptime n104plus - No
Operating System iptime n104plus-i_firmware ≤ 10.06.8 Yes
Hardware iptime n104plus-i - No
Operating System iptime n104q_firmware ≤ 10.06.8 Yes
Hardware iptime n104q - No
Operating System iptime n104q-i_firmware ≤ 10.06.8 Yes
Hardware iptime n104q-i - No
Operating System iptime n104r_firmware ≤ 10.06.8 Yes
Hardware iptime n104r - No
Operating System iptime n702eplus_firmware ≤ 12.16.2 Yes
Hardware iptime n702eplus - No
Operating System iptime n702r_firmware ≤ 10.06.8 Yes
Hardware iptime n702r - No
Operating System iptime n704-a3_firmware ≤ 10.06.8 Yes
Hardware iptime n704-a3 - No
Operating System iptime n704bcm_firmware ≤ 12.16.2 Yes
Hardware iptime n704bcm - No
Operating System iptime n704e_firmware ≤ 12.16.2 Yes
Hardware iptime n704e - No
Operating System iptime n704eplus_firmware ≤ 12.16.2 Yes
Hardware iptime n704eplus - No
Operating System iptime n704ns_firmware ≤ 9.96.0 Yes
Hardware iptime n704ns - No
Operating System iptime n704qca_firmware ≤ 12.16.2 Yes
Hardware iptime n704qca - No
Operating System iptime n704v3_firmware ≤ 12.10.2 Yes
Hardware iptime n704v3 - No
Operating System iptime n8004r_firmware ≤ 10.02.2 Yes
Hardware iptime n8004r - No
Operating System iptime n8004v_firmware ≤ 10.02.2 Yes
Hardware iptime n8004v - No
Operating System iptime n804_firmware ≤ 9.96.8 Yes
Hardware iptime n804 - No
Operating System iptime n804a_firmware ≤ 9.96.8 Yes
Hardware iptime n804a - No
Operating System iptime n804a3_firmware ≤ 9.96.8 Yes
Hardware iptime n804a3 - No
Operating System iptime n804r_firmware ≤ 12.16.2 Yes
Hardware iptime n804r - No
Operating System iptime n804t_firmware ≤ 9.96.8 Yes
Hardware iptime n804t - No
Operating System iptime n804t3_firmware ≤ 9.96.8 Yes
Hardware iptime n804t3 - No
Operating System iptime n804v_firmware ≤ 9.96.8 Yes
Hardware iptime n804v - No
Operating System iptime n904_firmware ≤ 10.02.2 Yes
Hardware iptime n904 - No
Operating System iptime n904ns_firmware ≤ 9.96.0 Yes
Hardware iptime n904ns - No
Operating System iptime n904plus_firmware ≤ 10.02.2 Yes
Hardware iptime n904plus - No
Operating System iptime n904v_firmware ≤ 10.02.2 Yes
Hardware iptime n904v - No
Operating System iptime smart_firmware ≤ 9.94.2 Yes
Hardware iptime smart - No
Operating System iptime q1_firmware 9.91.2 Yes
Hardware iptime q1 - No
Operating System iptime q304_firmware 9.91.2 Yes
Hardware iptime q304 - No
Operating System iptime q504_firmware 9.91.2 Yes
Hardware iptime q504 - No
Operating System iptime q604_firmware 9.91.2 Yes
Hardware iptime q604 - No
Operating System iptime t16000_firmware ≤ 11.03.6 Yes
Hardware iptime t16000 - No
Operating System iptime t16000m_firmware ≤ 14.19.4 Yes
Hardware iptime t16000m - No
Operating System iptime t24000_firmware ≤ 11.03.6 Yes
Hardware iptime t24000 - No
Operating System iptime t24000m_firmware ≤ 14.19.4 Yes
Hardware iptime t24000m - No
Operating System iptime t3004_firmware ≤ 12.07.6 Yes
Hardware iptime t3004 - No
Operating System iptime t3008_firmware ≤ 12.09.6 Yes
Hardware iptime t3008 - No
Operating System iptime t5004_firmware ≤ 14.19.4 Yes
Hardware iptime t5004 - No
Operating System iptime t5008_firmware ≤ 14.19.4 Yes
Hardware iptime t5008 - No
Operating System iptime v304_firmware 9.91.2 Yes
Hardware iptime v304 - No
Operating System iptime v504_firmware ≤ 12.15.2 Yes
Hardware iptime v504 - No
Operating System iptime v508_firmware ≤ 10.06.4 Yes
Hardware iptime v508 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For iptime's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.