Vulnerability Details CVE-2025-55423
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-55423
-
-
cpe:2.3:h:iptime:a1004ns:-
-
cpe:2.3:h:iptime:a1004v:-
-
-
cpe:2.3:h:iptime:a104ns:-
-
-
-
cpe:2.3:h:iptime:a2003mu:-
-
cpe:2.3:h:iptime:a2003ns-mu:-
-
-
cpe:2.3:h:iptime:a2004mu:-
-
cpe:2.3:h:iptime:a2004ns-mu:-
-
cpe:2.3:h:iptime:a2004ns-r:-
-
cpe:2.3:h:iptime:a2004ns:-
-
cpe:2.3:h:iptime:a2004nsplus:-
-
cpe:2.3:h:iptime:a2004plus:-
-
cpe:2.3:h:iptime:a2004r:-
-
cpe:2.3:h:iptime:a2004se:-
-
-
cpe:2.3:h:iptime:a3002mesh:-
-
cpe:2.3:h:iptime:a3003ns:-
-
cpe:2.3:h:iptime:a3004-dual:-
-
-
cpe:2.3:h:iptime:a3004m:-
-
cpe:2.3:h:iptime:a3004ns-bcm:-
-
cpe:2.3:h:iptime:a3004ns-dual:-
-
cpe:2.3:h:iptime:a3004ns-m:-
-
cpe:2.3:h:iptime:a3004ns:-
-
cpe:2.3:h:iptime:a3004t:-
-
cpe:2.3:h:iptime:a3004tw:-
-
cpe:2.3:h:iptime:a3008-mu:-
-
-
-
cpe:2.3:h:iptime:a5004ns-m:-
-
cpe:2.3:h:iptime:a5004ns:-
-
cpe:2.3:h:iptime:a6004mx:-
-
cpe:2.3:h:iptime:a6004ns-m:-
-
cpe:2.3:h:iptime:a6004ns:-
-
cpe:2.3:h:iptime:a604-v3:-
-
cpe:2.3:h:iptime:a604-v5:-
-
-
cpe:2.3:h:iptime:a604g-mu:-
-
cpe:2.3:h:iptime:a604g-skylife:-
-
-
cpe:2.3:h:iptime:a604mu:-
-
-
cpe:2.3:h:iptime:a604se:-
-
-
cpe:2.3:h:iptime:a6ns-m:-
-
cpe:2.3:h:iptime:a7004m:-
-
cpe:2.3:h:iptime:a704ns-bcm:-
-
-
cpe:2.3:h:iptime:a8004bcm:-
-
cpe:2.3:h:iptime:a8004itl:-
-
cpe:2.3:h:iptime:a8004ns-m:-
-
cpe:2.3:h:iptime:a8004t-xr:-
-
cpe:2.3:h:iptime:a8004t:-
-
cpe:2.3:h:iptime:a804ns-mu:-
-
cpe:2.3:h:iptime:a8ns-m:-
-
cpe:2.3:h:iptime:a9004m-x2:-
-
cpe:2.3:h:iptime:a9004m:-
-
cpe:2.3:h:iptime:ax11000:-
-
cpe:2.3:h:iptime:ax2002mesh:-
-
cpe:2.3:h:iptime:ax2004:-
-
cpe:2.3:h:iptime:ax2004bcm:-
-
cpe:2.3:h:iptime:ax2004m:-
-
cpe:2.3:h:iptime:ax3004bcm:-
-
cpe:2.3:h:iptime:ax3004itl:-
-
cpe:2.3:h:iptime:ax8004bcm:-
-
cpe:2.3:h:iptime:ax8004m:-
-
cpe:2.3:h:iptime:ax8008m:-
-
cpe:2.3:h:iptime:ew302n:-
-
-
cpe:2.3:h:iptime:n102eplus:-
-
-
cpe:2.3:h:iptime:n102iplus:-
-
cpe:2.3:h:iptime:n104_black:-
-
-
cpe:2.3:h:iptime:n104eplus:-
-
-
cpe:2.3:h:iptime:n104plus-i:-
-
cpe:2.3:h:iptime:n104plus:-
-
cpe:2.3:h:iptime:n104q-i:-
-
-
-
cpe:2.3:h:iptime:n104s-r1:-
-
-
-
cpe:2.3:h:iptime:n1plus-i:-
-
cpe:2.3:h:iptime:n1plus:-
-
-
-
cpe:2.3:h:iptime:n2eplus:-
-
cpe:2.3:h:iptime:n2plus-i:-
-
cpe:2.3:h:iptime:n2plus:-
-
-
-
-
-
-
-
cpe:2.3:h:iptime:n6004r:-
-
-
-
cpe:2.3:h:iptime:n602eplus:-
-
cpe:2.3:h:iptime:n602se:-
-
cpe:2.3:h:iptime:n604_black:-
-
-
-
cpe:2.3:h:iptime:n604eplus:-
-
cpe:2.3:h:iptime:n604plus-i:-
-
cpe:2.3:h:iptime:n604plus:-
-
-
cpe:2.3:h:iptime:n604rplus-i:-
-
cpe:2.3:h:iptime:n604rplus:-
-
-
cpe:2.3:h:iptime:n604se:-
-
-
cpe:2.3:h:iptime:n604tplus:-
-
-
cpe:2.3:h:iptime:n604vplus:-
-
-
cpe:2.3:h:iptime:n7004ns:-
-
cpe:2.3:h:iptime:n702bcm:-
-
-
cpe:2.3:h:iptime:n702eplus:-
-
-
cpe:2.3:h:iptime:n704-a3:-
-
cpe:2.3:h:iptime:n704bcm:-
-
-
cpe:2.3:h:iptime:n704eplus:-
-
cpe:2.3:h:iptime:n704ns:-
-
cpe:2.3:h:iptime:n704qca:-
-
cpe:2.3:h:iptime:n704v3:-
-
cpe:2.3:h:iptime:n8004r:-
-
cpe:2.3:h:iptime:n8004v:-
-
-
cpe:2.3:h:iptime:n804a3:-
-
-
-
cpe:2.3:h:iptime:n804t3:-
-
-
-
-
cpe:2.3:h:iptime:n904ns:-
-
cpe:2.3:h:iptime:n904plus:-
-
-
-
-
-
-
-
cpe:2.3:h:iptime:t16000:-
-
cpe:2.3:h:iptime:t16000m:-
-
cpe:2.3:h:iptime:t24000:-
-
cpe:2.3:h:iptime:t24000m:-
-
-
-
-
-
-
-
-
cpe:2.3:o:iptime:a1004_firmware:*
-
cpe:2.3:o:iptime:a1004ns_firmware:*
-
cpe:2.3:o:iptime:a1004v_firmware:*
-
cpe:2.3:o:iptime:a104_firmware:*
-
cpe:2.3:o:iptime:a104ns_firmware:*
-
cpe:2.3:o:iptime:a104r_firmware:*
-
cpe:2.3:o:iptime:a104r_firmware:-
-
cpe:2.3:o:iptime:a1_firmware:*
-
cpe:2.3:o:iptime:a2003mu_firmware:*
-
cpe:2.3:o:iptime:a2003ns-mu_firmware:*
-
cpe:2.3:o:iptime:a2004_firmware:*
-
cpe:2.3:o:iptime:a2004mu_firmware:*
-
cpe:2.3:o:iptime:a2004ns-mu_firmware:*
-
cpe:2.3:o:iptime:a2004ns-r_firmware:*
-
cpe:2.3:o:iptime:a2004ns_firmware:*
-
cpe:2.3:o:iptime:a2004nsplus_firmware:*
-
cpe:2.3:o:iptime:a2004plus_firmware:*
-
cpe:2.3:o:iptime:a2004r_firmware:*
-
cpe:2.3:o:iptime:a2004se_firmware:*
-
cpe:2.3:o:iptime:a2008_firmware:*
-
cpe:2.3:o:iptime:a3002mesh_firmware:*
-
cpe:2.3:o:iptime:a3003ns_firmware:*
-
cpe:2.3:o:iptime:a3004-dual_firmware:*
-
cpe:2.3:o:iptime:a3004_firmware:*
-
cpe:2.3:o:iptime:a3004m_firmware:*
-
cpe:2.3:o:iptime:a3004ns-bcm_firmware:*
-
cpe:2.3:o:iptime:a3004ns-dual_firmware:*
-
cpe:2.3:o:iptime:a3004ns-m_firmware:*
-
cpe:2.3:o:iptime:a3004ns_firmware:*
-
cpe:2.3:o:iptime:a3004t_firmware:*
-
cpe:2.3:o:iptime:a3004tw_firmware:*
-
cpe:2.3:o:iptime:a3008-mu_firmware:*
-
cpe:2.3:o:iptime:a304_firmware:*
-
cpe:2.3:o:iptime:a3_firmware:*
-
cpe:2.3:o:iptime:a5004ns-m_firmware:*
-
cpe:2.3:o:iptime:a5004ns_firmware:*
-
cpe:2.3:o:iptime:a6004mx_firmware:*
-
cpe:2.3:o:iptime:a6004ns-m_firmware:*
-
cpe:2.3:o:iptime:a6004ns_firmware:*
-
cpe:2.3:o:iptime:a604-v3_firmware:*
-
cpe:2.3:o:iptime:a604-v5_firmware:*
-
cpe:2.3:o:iptime:a604_firmware:*
-
cpe:2.3:o:iptime:a604g-mu_firmware:*
-
cpe:2.3:o:iptime:a604g-skylife_firmware:*
-
cpe:2.3:o:iptime:a604m_firmware:*
-
cpe:2.3:o:iptime:a604mu_firmware:*
-
cpe:2.3:o:iptime:a604r_firmware:*
-
cpe:2.3:o:iptime:a604se_firmware:*
-
cpe:2.3:o:iptime:a604v_firmware:*
-
cpe:2.3:o:iptime:a6ns-m_firmware:*
-
cpe:2.3:o:iptime:a7004m_firmware:*
-
cpe:2.3:o:iptime:a704ns-bcm_firmware:*
-
cpe:2.3:o:iptime:a7ns_firmware:*
-
cpe:2.3:o:iptime:a8004bcm_firmware:*
-
cpe:2.3:o:iptime:a8004itl_firmware:*
-
cpe:2.3:o:iptime:a8004ns-m_firmware:*
-
cpe:2.3:o:iptime:a8004t-xr_firmware:*
-
cpe:2.3:o:iptime:a8004t_firmware:*
-
cpe:2.3:o:iptime:a804ns-mu_firmware:*
-
cpe:2.3:o:iptime:a8ns-m_firmware:*
-
cpe:2.3:o:iptime:a9004m-x2_firmware:*
-
cpe:2.3:o:iptime:a9004m_firmware:*
-
cpe:2.3:o:iptime:ax11000_firmware:*
-
cpe:2.3:o:iptime:ax2002mesh_firmware:*
-
cpe:2.3:o:iptime:ax2004_firmware:*
-
cpe:2.3:o:iptime:ax2004bcm_firmware:*
-
cpe:2.3:o:iptime:ax2004m_firmware:*
-
cpe:2.3:o:iptime:ax3004bcm_firmware:*
-
cpe:2.3:o:iptime:ax3004itl_firmware:*
-
cpe:2.3:o:iptime:ax8004bcm_firmware:*
-
cpe:2.3:o:iptime:ax8004m_firmware:*
-
cpe:2.3:o:iptime:ax8008m_firmware:*
-
cpe:2.3:o:iptime:ew302n_firmware:*
-
cpe:2.3:o:iptime:n102e_firmware:*
-
cpe:2.3:o:iptime:n102eplus_firmware:*
-
cpe:2.3:o:iptime:n102i_firmware:*
-
cpe:2.3:o:iptime:n102iplus_firmware:*
-
cpe:2.3:o:iptime:n104_black_firmware:*
-
cpe:2.3:o:iptime:n104e_firmware:*
-
cpe:2.3:o:iptime:n104eplus_firmware:*
-
cpe:2.3:o:iptime:n104k_firmware:*
-
cpe:2.3:o:iptime:n104plus-i_firmware:*
-
cpe:2.3:o:iptime:n104plus_firmware:*
-
cpe:2.3:o:iptime:n104q-i_firmware:*
-
cpe:2.3:o:iptime:n104q_firmware:*
-
cpe:2.3:o:iptime:n104r_firmware:*
-
cpe:2.3:o:iptime:n104s-r1_firmware:*
-
cpe:2.3:o:iptime:n104v_firmware:*
-
cpe:2.3:o:iptime:n1e_firmware:*
-
cpe:2.3:o:iptime:n1plus-i_firmware:*
-
cpe:2.3:o:iptime:n1plus_firmware:*
-
cpe:2.3:o:iptime:n1v_firmware:*
-
cpe:2.3:o:iptime:n2e_firmware:*
-
cpe:2.3:o:iptime:n2eplus_firmware:*
-
cpe:2.3:o:iptime:n2plus-i_firmware:*
-
cpe:2.3:o:iptime:n2plus_firmware:*
-
cpe:2.3:o:iptime:n2v_firmware:*
-
cpe:2.3:o:iptime:n2vs_firmware:12.16.8
-
cpe:2.3:o:iptime:n3-i_firmware:*
-
cpe:2.3:o:iptime:n3_firmware:*
-
cpe:2.3:o:iptime:n5-i_firmware:*
-
cpe:2.3:o:iptime:n5_firmware:*
-
cpe:2.3:o:iptime:n6004r_firmware:*
-
cpe:2.3:o:iptime:n600_firmware:*
-
cpe:2.3:o:iptime:n602e_firmware:*
-
cpe:2.3:o:iptime:n602eplus_firmware:*
-
cpe:2.3:o:iptime:n602se_firmware:*
-
cpe:2.3:o:iptime:n604_black_firmware:*
-
cpe:2.3:o:iptime:n604a_firmware:*
-
cpe:2.3:o:iptime:n604e_firmware:*
-
cpe:2.3:o:iptime:n604eplus_firmware:*
-
cpe:2.3:o:iptime:n604plus-i_firmware:*
-
cpe:2.3:o:iptime:n604plus_firmware:*
-
cpe:2.3:o:iptime:n604r_firmware:*
-
cpe:2.3:o:iptime:n604rplus-i_firmware:*
-
cpe:2.3:o:iptime:n604rplus_firmware:*
-
cpe:2.3:o:iptime:n604s_firmware:*
-
cpe:2.3:o:iptime:n604se_firmware:*
-
cpe:2.3:o:iptime:n604t_firmware:*
-
cpe:2.3:o:iptime:n604tplus_firmware:*
-
cpe:2.3:o:iptime:n604v_firmware:*
-
cpe:2.3:o:iptime:n604vplus_firmware:*
-
cpe:2.3:o:iptime:n6_firmware:*
-
cpe:2.3:o:iptime:n7004ns_firmware:9.91.2
-
cpe:2.3:o:iptime:n702bcm_firmware:*
-
cpe:2.3:o:iptime:n702e_firmware:*
-
cpe:2.3:o:iptime:n702eplus_firmware:*
-
cpe:2.3:o:iptime:n702r_firmware:*
-
cpe:2.3:o:iptime:n704-a3_firmware:*
-
cpe:2.3:o:iptime:n704bcm_firmware:*
-
cpe:2.3:o:iptime:n704e_firmware:*
-
cpe:2.3:o:iptime:n704eplus_firmware:*
-
cpe:2.3:o:iptime:n704ns_firmware:*
-
cpe:2.3:o:iptime:n704qca_firmware:*
-
cpe:2.3:o:iptime:n704v3_firmware:*
-
cpe:2.3:o:iptime:n8004r_firmware:*
-
cpe:2.3:o:iptime:n8004v_firmware:*
-
cpe:2.3:o:iptime:n804_firmware:*
-
cpe:2.3:o:iptime:n804a3_firmware:*
-
cpe:2.3:o:iptime:n804a_firmware:*
-
cpe:2.3:o:iptime:n804r_firmware:*
-
cpe:2.3:o:iptime:n804t3_firmware:*
-
cpe:2.3:o:iptime:n804t_firmware:*
-
cpe:2.3:o:iptime:n804v_firmware:*
-
cpe:2.3:o:iptime:n904_firmware:*
-
cpe:2.3:o:iptime:n904ns_firmware:*
-
cpe:2.3:o:iptime:n904plus_firmware:*
-
cpe:2.3:o:iptime:n904v_firmware:*
-
cpe:2.3:o:iptime:q1_firmware:9.91.2
-
cpe:2.3:o:iptime:q304_firmware:9.91.2
-
cpe:2.3:o:iptime:q504_firmware:9.91.2
-
cpe:2.3:o:iptime:q604_firmware:9.91.2
-
cpe:2.3:o:iptime:smart_firmware:*
-
cpe:2.3:o:iptime:t16000_firmware:*
-
cpe:2.3:o:iptime:t16000m_firmware:*
-
cpe:2.3:o:iptime:t24000_firmware:*
-
cpe:2.3:o:iptime:t24000m_firmware:*
-
cpe:2.3:o:iptime:t3004_firmware:*
-
cpe:2.3:o:iptime:t3008_firmware:*
-
cpe:2.3:o:iptime:t5004_firmware:*
-
cpe:2.3:o:iptime:t5008_firmware:*
-
cpe:2.3:o:iptime:v304_firmware:9.91.2
-
cpe:2.3:o:iptime:v504_firmware:*
-
cpe:2.3:o:iptime:v508_firmware:*