CVE-2025-55423
CRITICAL EPSS 87.1%
Published Jan 20, 20265mo ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Published Jan 20, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago
Description
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
87.1% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-94 Improper Control of Generation of Code (Code Injection) Injection
Affected Products 327
| Vendor | Product | Version | Range |
|---|---|---|---|
| iptime | n104s-r1_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n104s-r1 | * | any |
| iptime | n104v_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n104v | * | any |
| iptime | n1e_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n1e | * | any |
| iptime | n1plus_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n1plus | * | any |
| iptime | n1plus-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n1plus-i | * | any |
| iptime | n1v_firmware | * | ≥11.01.2 – ≤12.07.6 |
| iptime | n1v | * | any |
| iptime | n2e_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n2e | * | any |
| iptime | n2eplus_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n2eplus | * | any |
| iptime | n2plus_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n2plus | * | any |
| iptime | n2plus-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n2plus-i | * | any |
| iptime | n2v_firmware | * | ≥10.09.2 – ≤12.16.8 |
| iptime | n2v | * | any |
| iptime | n2vs_firmware | 12.16.8 | any |
| iptime | n2vs | * | any |
| iptime | n3_firmware | * | ≥9.93.2 – ≤10.06.8 |
| iptime | n3 | * | any |
| iptime | n3-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n3-i | * | any |
| iptime | n5_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n5 | * | any |
| iptime | n5-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n5-i | * | any |
| iptime | n6_firmware | * | ≥9.96.8 – ≤10.06.8 |
| iptime | n6 | * | any |
| iptime | n600_firmware | * | ≥10.00.8 – ≤12.16.2 |
| iptime | n600 | * | any |
| iptime | n6004r_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n6004r | * | any |
| iptime | n602e_firmware | * | ≥11.96.6 – ≤12.16.8 |
| iptime | n602e | * | any |
| iptime | n602eplus_firmware | * | ≥12.14.2 – ≤12.16.2 |
| iptime | n602eplus | * | any |
| iptime | n602se_firmware | * | ≥14.19.0 – ≤14.19.4 |
| iptime | n602se | * | any |
| iptime | n604_black_firmware | * | ≥9.93.8 – ≤12.16.2 |
| iptime | n604_black | * | any |
| iptime | n604a_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n604a | * | any |
| iptime | n604e_firmware | * | ≥10.09.2 – ≤14.19.4 |
| iptime | n604e | * | any |
| iptime | n604eplus_firmware | * | ≥12.14.2 – ≤14.19.4 |
| iptime | n604eplus | * | any |
| iptime | n604plus_firmware | * | ≥9.90.8 – ≤12.15.2 |
| iptime | n604plus | * | any |
| iptime | n604plus-i_firmware | * | ≥9.99.6 – ≤12.14.6 |
| iptime | n604plus-i | * | any |
| iptime | n604r_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n604r | * | any |
| iptime | n604rplus_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n604rplus | * | any |
| iptime | n604rplus-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n604rplus-i | * | any |
| iptime | n604s_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n604s | * | any |
| iptime | n604se_firmware | * | ≥14.18.4 – ≤14.19.4 |
| iptime | n604se | * | any |
| iptime | n604t_firmware | * | ≥9.90.8 – ≤10.03.2 |
| iptime | n604t | * | any |
| iptime | n604tplus_firmware | * | ≥9.90.8 – ≤10.03.2 |
| iptime | n604tplus | * | any |
| iptime | n604v_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n604v | * | any |
| iptime | n604vplus_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n604vplus | * | any |
| iptime | n7004ns_firmware | 9.91.2 | any |
| iptime | n7004ns | * | any |
| iptime | n702bcm_firmware | * | ≥9.90.8 – ≤12.16.2 |
| iptime | n702bcm | * | any |
| iptime | n702e_firmware | * | ≥10.09.2 – ≤12.16.2 |
| iptime | n702e | * | any |
| iptime | ax11000_firmware | * | ≥14.16.6 – ≤14.19.4 |
| iptime | ax11000 | * | any |
| iptime | ax2002mesh_firmware | * | ≥14.16.6 – ≤14.19.4 |
| iptime | ax2002mesh | * | any |
| iptime | ax2004_firmware | * | ≥14.17.4 – ≤14.19.4 |
| iptime | ax2004 | * | any |
| iptime | ax2004bcm_firmware | * | ≥12.04.2 – ≤14.19.4 |
| iptime | ax2004bcm | * | any |
| iptime | ax2004m_firmware | * | ≥14.02.0 – ≤14.19.4 |
| iptime | ax2004m | * | any |
| iptime | ax3004bcm_firmware | * | ≥14.16.2 – ≤14.19.4 |
| iptime | ax3004bcm | * | any |
| iptime | ax3004itl_firmware | * | ≥12.01.2 – ≤14.19.4 |
| iptime | ax3004itl | * | any |
| iptime | ax8004bcm_firmware | * | ≥11.97.2 – ≤14.19.4 |
| iptime | ax8004bcm | * | any |
| iptime | ax8004m_firmware | * | ≥14.05.2 – ≤14.19.4 |
| iptime | ax8004m | * | any |
| iptime | ax8008m_firmware | * | ≥14.15.4 – ≤14.19.4 |
| iptime | ax8008m | * | any |
| iptime | a1_firmware | * | ≥9.96.8 – ≤10.07.4 |
| iptime | a1 | * | any |
| iptime | a1004_firmware | * | ≥9.90.8 – ≤12.16.2 |
| iptime | a1004 | * | any |
| iptime | a1004ns_firmware | * | ≥9.96.0 – ≤12.16.2 |
| iptime | a1004ns | * | any |
| iptime | a1004v_firmware | * | ≥9.90.8 – ≤12.16.2 |
| iptime | a1004v | * | any |
| iptime | a104_firmware | * | ≥9.90.8 – ≤10.03.8 |
| iptime | a104 | * | any |
| iptime | a104ns_firmware | * | ≥9.96.0 – ≤12.16.2 |
| iptime | a104ns | * | any |
| iptime | a104r_firmware | * | ≥9.90.8 – ≤10.07.4 |
| iptime | a104r_firmware | * | any |
| iptime | a104r | * | any |
| iptime | a2003mu_firmware | * | ≥12.13.0 – ≤12.16.2 |
| iptime | a2003mu | * | any |
| iptime | a2003ns-mu_firmware | * | ≥10.00.6 – ≤12.16.2 |
| iptime | a2003ns-mu | * | any |
| iptime | a2004_firmware | * | ≥9.90.8 – ≤10.07.4 |
| iptime | a2004 | * | any |
| iptime | a2004mu_firmware | * | ≥10.08.6 – ≤12.17.0 |
| iptime | a2004mu | * | any |
| iptime | a2004ns_firmware | * | ≥9.90.8 – ≤11.00.4 |
| iptime | a2004ns | * | any |
| iptime | a2004ns-mu_firmware | * | ≥10.08.6 – ≤12.17.0 |
| iptime | a2004ns-mu | * | any |
| iptime | a2004ns-r_firmware | * | ≥9.90.8 – ≤11.00.4 |
| iptime | a2004ns-r | * | any |
| iptime | a2004nsplus_firmware | * | ≥9.90.8 – ≤11.00.4 |
| iptime | a2004nsplus | * | any |
| iptime | a2004plus_firmware | * | ≥9.90.8 – ≤10.07.4 |
| iptime | a2004plus | * | any |
| iptime | a2004r_firmware | * | ≥9.90.8 – ≤10.07.4 |
| iptime | a2004r | * | any |
| iptime | a2004se_firmware | * | ≥14.16.6 – ≤14.19.4 |
| iptime | a2004se | * | any |
| iptime | a2008_firmware | * | ≥9.90.8 – ≤10.07.4 |
| iptime | a2008 | * | any |
| iptime | a3_firmware | * | ≥9.97.2 – ≤10.07.2 |
| iptime | a3 | * | any |
| iptime | a3002mesh_firmware | * | ≥12.05.4 – ≤14.19.4 |
| iptime | a3002mesh | * | any |
| iptime | a3003ns_firmware | * | ≥9.99.8 – ≤11.00.4 |
| iptime | a3003ns | * | any |
| iptime | a3004_firmware | * | ≥9.90.8 – ≤10.08.2 |
| iptime | a3004 | * | any |
| iptime | a3004-dual_firmware | * | ≥9.90.4 – ≤10.07.2 |
| iptime | a3004-dual | * | any |
| iptime | a3004m_firmware | * | ≥14.18.4 – ≤14.19.4 |
| iptime | a3004m | * | any |
| iptime | a3004ns_firmware | * | ≥9.90.2 – ≤10.09.4 |
| iptime | a3004ns | * | any |
| iptime | a3004ns-bcm_firmware | * | ≥9.95.8 – ≤11.00.4 |
| iptime | a3004ns-bcm | * | any |
| iptime | a3004ns-dual_firmware | * | ≥9.90.4 – ≤12.09.4 |
| iptime | a3004ns-dual | * | any |
| iptime | a3004ns-m_firmware | * | ≥10.05.4 – ≤14.19.4 |
| iptime | a3004ns-m | * | any |
| iptime | a3004t_firmware | * | ≥12.10.2 – ≤14.19.4 |
| iptime | a3004t | * | any |
| iptime | a3004tw_firmware | * | ≥14.15.2 – ≤14.19.4 |
| iptime | a3004tw | * | any |
| iptime | a3008-mu_firmware | * | ≥10.08.4 – ≤14.19.4 |
| iptime | a3008-mu | * | any |
| iptime | a304_firmware | * | ≥10.05.4 – ≤10.07.4 |
| iptime | a304 | * | any |
| iptime | a5004ns_firmware | * | ≥9.90.2 – ≤11.00.4 |
| iptime | a5004ns | * | any |
| iptime | a5004ns-m_firmware | * | ≥10.05.4 – ≤14.19.4 |
| iptime | a5004ns-m | * | any |
| iptime | a6004mx_firmware | * | ≥12.04.6 – ≤14.19.4 |
| iptime | a6004mx | * | any |
| iptime | a6004ns_firmware | * | ≥9.90.2 – ≤11.00.4 |
| iptime | a6004ns | * | any |
| iptime | a6004ns-m_firmware | * | ≥9.99.8 – ≤14.19.4 |
| iptime | a6004ns-m | * | any |
| iptime | a604_firmware | * | ≥9.90.8 – ≤12.06.6 |
| iptime | a604 | * | any |
| iptime | a604-v3_firmware | * | ≥10.01.6 – ≤10.07.2 |
| iptime | a604-v3 | * | any |
| iptime | a604-v5_firmware | * | ≥10.09.2 – ≤12.16.2 |
| iptime | a604-v5 | * | any |
| iptime | a604g-mu_firmware | * | ≥10.07.4 – ≤12.16.2 |
| iptime | a604g-mu | * | any |
| iptime | a604g-skylife_firmware | * | ≥12.02.4 – ≤12.12.4 |
| iptime | a604g-skylife | * | any |
| iptime | a604m_firmware | * | ≥10.06.4 – ≤10.07.2 |
| iptime | a604m | * | any |
| iptime | a604mu_firmware | * | ≥12.12.4 – ≤12.16.2 |
| iptime | a604mu | * | any |
| iptime | a604r_firmware | * | ≥10.09.2 – ≤12.16.2 |
| iptime | a604r | * | any |
| iptime | a604se_firmware | * | ≥14.17.2 – ≤14.19.4 |
| iptime | a604se | * | any |
| iptime | a604v_firmware | * | ≥9.90.8 – ≤10.07.4 |
| iptime | a604v | * | any |
| iptime | a6ns-m_firmware | * | ≥10.01.6 – ≤14.19.4 |
| iptime | a6ns-m | * | any |
| iptime | a7004m_firmware | * | ≥10.06.8 – ≤14.19.4 |
| iptime | a7004m | * | any |
| iptime | a704ns-bcm_firmware | * | ≥9.95.8 – ≤11.00.4 |
| iptime | a704ns-bcm | * | any |
| iptime | a7ns_firmware | * | ≥9.96.0 – ≤11.00.4 |
| iptime | a7ns | * | any |
| iptime | a8004bcm_firmware | * | ≥11.99.1 – ≤12.16.2 |
| iptime | a8004bcm | * | any |
| iptime | a8004itl_firmware | * | ≥11.00.4 – ≤14.19.4 |
| iptime | a8004itl | * | any |
| iptime | a8004ns-m_firmware | * | ≥9.99.2 – ≤14.19.4 |
| iptime | a8004ns-m | * | any |
| iptime | a8004t_firmware | * | ≥10.06.8 – ≤14.19.4 |
| iptime | a8004t | * | any |
| iptime | a8004t-xr_firmware | * | ≥11.97.2 – ≤14.19.4 |
| iptime | a8004t-xr | * | any |
| iptime | a804ns-mu_firmware | * | ≥10.06.4 – ≤12.10.2 |
| iptime | a804ns-mu | * | any |
| iptime | a8ns-m_firmware | * | ≥10.03.2 – ≤14.19.4 |
| iptime | a8ns-m | * | any |
| iptime | a9004m_firmware | * | ≥10.05.4 – ≤14.19.4 |
| iptime | a9004m | * | any |
| iptime | a9004m-x2_firmware | * | ≥11.98.2 – ≤14.19.4 |
| iptime | a9004m-x2 | * | any |
| iptime | ew302n_firmware | * | ≥9.90.8 – ≤12.16.2 |
| iptime | ew302n | * | any |
| iptime | n102e_firmware | * | ≥11.00.8 – ≤12.15.2 |
| iptime | n102e | * | any |
| iptime | n102eplus_firmware | * | ≥12.14.2 – ≤12.15.2 |
| iptime | n102eplus | * | any |
| iptime | n102i_firmware | * | ≥11.01.2 – ≤12.15.2 |
| iptime | n102i | * | any |
| iptime | n102iplus_firmware | * | ≥12.14.2 – ≤12.15.2 |
| iptime | n102iplus | * | any |
| iptime | n104_black_firmware | * | ≥9.93.8 – ≤10.06.8 |
| iptime | n104_black | * | any |
| iptime | n104e_firmware | * | ≥10.09.4 – ≤12.15.2 |
| iptime | n104e | * | any |
| iptime | n104eplus_firmware | * | ≥12.14.2 – ≤12.15.2 |
| iptime | n104eplus | * | any |
| iptime | n104k_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n104k | * | any |
| iptime | n104plus_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n104plus | * | any |
| iptime | n104plus-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n104plus-i | * | any |
| iptime | n104q_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n104q | * | any |
| iptime | n104q-i_firmware | * | ≥9.99.6 – ≤10.06.8 |
| iptime | n104q-i | * | any |
| iptime | n104r_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n104r | * | any |
| iptime | n702eplus_firmware | * | ≥12.12.4 – ≤12.16.2 |
| iptime | n702eplus | * | any |
| iptime | n702r_firmware | * | ≥10.05.8 – ≤10.06.8 |
| iptime | n702r | * | any |
| iptime | n704-a3_firmware | * | ≥9.90.8 – ≤10.06.8 |
| iptime | n704-a3 | * | any |
| iptime | n704bcm_firmware | * | ≥9.90.8 – ≤12.16.2 |
| iptime | n704bcm | * | any |
| iptime | n704e_firmware | * | ≥11.98.4 – ≤12.16.2 |
| iptime | n704e | * | any |
| iptime | n704eplus_firmware | * | ≥12.14.2 – ≤12.16.2 |
| iptime | n704eplus | * | any |
| iptime | n704ns_firmware | * | ≥9.91.4 – ≤9.96.0 |
| iptime | n704ns | * | any |
| iptime | n704qca_firmware | * | ≥10.02.4 – ≤12.16.2 |
| iptime | n704qca | * | any |
| iptime | n704v3_firmware | * | ≥9.90.8 – ≤12.10.2 |
| iptime | n704v3 | * | any |
| iptime | n8004r_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n8004r | * | any |
| iptime | n8004v_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n8004v | * | any |
| iptime | n804_firmware | * | ≥9.91.2 – ≤9.96.8 |
| iptime | n804 | * | any |
| iptime | n804a_firmware | * | ≥9.91.2 – ≤9.96.8 |
| iptime | n804a | * | any |
| iptime | n804a3_firmware | * | ≥9.90.8 – ≤9.96.8 |
| iptime | n804a3 | * | any |
| iptime | n804r_firmware | * | ≥10.06.4 – ≤12.16.2 |
| iptime | n804r | * | any |
| iptime | n804t_firmware | * | ≥9.91.2 – ≤9.96.8 |
| iptime | n804t | * | any |
| iptime | n804t3_firmware | * | ≥9.90.8 – ≤9.96.8 |
| iptime | n804t3 | * | any |
| iptime | n804v_firmware | * | ≥9.91.2 – ≤9.96.8 |
| iptime | n804v | * | any |
| iptime | n904_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n904 | * | any |
| iptime | n904ns_firmware | * | ≥9.91.4 – ≤9.96.0 |
| iptime | n904ns | * | any |
| iptime | n904plus_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n904plus | * | any |
| iptime | n904v_firmware | * | ≥9.90.8 – ≤10.02.2 |
| iptime | n904v | * | any |
| iptime | smart_firmware | * | ≥9.90.8 – ≤9.94.2 |
| iptime | smart | * | any |
| iptime | q1_firmware | 9.91.2 | any |
| iptime | q1 | * | any |
| iptime | q304_firmware | 9.91.2 | any |
| iptime | q304 | * | any |
| iptime | q504_firmware | 9.91.2 | any |
| iptime | q504 | * | any |
| iptime | q604_firmware | 9.91.2 | any |
| iptime | q604 | * | any |
| iptime | t16000_firmware | * | ≥9.91.2 – ≤11.03.6 |
| iptime | t16000 | * | any |
| iptime | t16000m_firmware | * | ≥12.07.4 – ≤14.19.4 |
| iptime | t16000m | * | any |
| iptime | t24000_firmware | * | ≥9.91.2 – ≤11.03.6 |
| iptime | t24000 | * | any |
| iptime | t24000m_firmware | * | ≥12.07.4 – ≤14.19.4 |
| iptime | t24000m | * | any |
| iptime | t3004_firmware | * | ≥9.90.8 – ≤12.07.6 |
| iptime | t3004 | * | any |
| iptime | t3008_firmware | * | ≥9.90.8 – ≤12.09.6 |
| iptime | t3008 | * | any |
| iptime | t5004_firmware | * | ≥11.96.4 – ≤14.19.4 |
| iptime | t5004 | * | any |
| iptime | t5008_firmware | * | ≥11.98.2 – ≤14.19.4 |
| iptime | t5008 | * | any |
| iptime | v304_firmware | 9.91.2 | any |
| iptime | v304 | * | any |
| iptime | v504_firmware | * | ≥9.90.8 – ≤12.15.2 |
| iptime | v504 | * | any |
| iptime | v508_firmware | * | ≥10.02.2 – ≤10.06.4 |
| iptime | v508 | * | any |
References 4
- docs.google.com https://docs.google.com/spreadsheets/d/1kryOFltCmnPJvDTpIrudgryt79uI4PWchuQ8-Gak24c/edit?usp=sharing
- github.com https://github.com/0x0xxxx/CVE/blob/main/CVE-2025-55423/README.md
- github.com https://github.com/0x0xxxx/CVE/blob/main/CVE-2025-55423/assets/affected_products_cve_format.json
- iptime.com https://iptime.com/iptime/?pageid=4&page_id=126&dfsid=3&dftid=583&uid=25203&mod=document
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.