A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Metrics
Affected Vendors & Products
References
History
Wed, 21 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ipTIME routers A2003NS-MU 10.00.6 to 12.16.2 , N600 10.00.8 to 12.16.2, A604-V3 10.01.6 to 10.07.2, A6ns-M 10.01.6 to 14.19.4 , V508 10.02.2 to 10.06.4, N704QCA 10.02.4 to 12.16.2, A8ns-M 10.03.2 to 14.19.4, A304 10.05.4 to 10.07.4, A3004NS-M,A5004NS-M,A9004M 10.05.4 to 14.19.4, N702R 10.05.8 to 10.06.8, A604M 10.06.4 to 10.07.2, A804NS-MU 10.06.4 to 12.10.2, N804R 10.06.4 to 12.16.2, A7004M,A8004T 10.06.8 to 14.19.4, A604G-MU 10.07.4 to 12.16.2, A3008-MU 10.08.4 to 14.19.4, A2004MU and A2004NS-MU 10.08.6 to 12.17.0, A604-V5,A604R, N702E 10.09.2 to 12.16.2, N2V 10.09.2 to 12.16.8, N604E 10.09.2 to 14.19.4, N104E 10.09.4 to 12.15.2, A8004ITL 11.00.4 to 14.19.4, N102E 11.00.8 to 12.15.2, N1V 11.01.2 to 12.07.6, N102i 11.01.2 to 12.15.2, T5004 11.96.4 to 14.19.4, N602E 11.96.6 to 12.16.8, AX8004BCM and A8004T-XR 11.97.2 to 14.19.4, A9004M-X2, T5008 11.98.2 to 14.19.4, N704E 11.98.4 to 12.16.2, A8004BCM 11.99.1 to 12.16.2, AX3004ITL 12.01.2 to 14.19.4 and A604G-skylife 12.02.4 to 12.12 were discovered to contain an OS command injection vulnerability via the function upnp_relay(). | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iptime
Iptime a2003ns-mu Iptime a2004mu Iptime a2004ns-mu Iptime a3004ns-m Iptime a3008-mu Iptime a304 Iptime a5004ns-m Iptime a604-v3 Iptime a604-v5 Iptime a604g-mu Iptime a604g-skylife Iptime a604m Iptime a604r Iptime a6ns-m Iptime a7004m Iptime a8004bcm Iptime a8004itl Iptime a8004t Iptime a8004t-xr Iptime a804ns-mu Iptime a8ns-m Iptime a9004m Iptime a9004m-x2 Iptime ax3004itl Iptime ax8004bcm Iptime n102e Iptime n102i Iptime n104e Iptime n1v Iptime n2v Iptime n600 Iptime n602e Iptime n604e Iptime n702e Iptime n702r Iptime n704e Iptime n704qca Iptime n804r Iptime t5004 Iptime t5008 Iptime v508 |
|
| Vendors & Products |
Iptime
Iptime a2003ns-mu Iptime a2004mu Iptime a2004ns-mu Iptime a3004ns-m Iptime a3008-mu Iptime a304 Iptime a5004ns-m Iptime a604-v3 Iptime a604-v5 Iptime a604g-mu Iptime a604g-skylife Iptime a604m Iptime a604r Iptime a6ns-m Iptime a7004m Iptime a8004bcm Iptime a8004itl Iptime a8004t Iptime a8004t-xr Iptime a804ns-mu Iptime a8ns-m Iptime a9004m Iptime a9004m-x2 Iptime ax3004itl Iptime ax8004bcm Iptime n102e Iptime n102i Iptime n104e Iptime n1v Iptime n2v Iptime n600 Iptime n602e Iptime n604e Iptime n702e Iptime n702r Iptime n704e Iptime n704qca Iptime n804r Iptime t5004 Iptime t5008 Iptime v508 |
Tue, 20 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ipTIME routers A2003NS-MU 10.00.6 to 12.16.2 , N600 10.00.8 to 12.16.2, A604-V3 10.01.6 to 10.07.2, A6ns-M 10.01.6 to 14.19.4 , V508 10.02.2 to 10.06.4, N704QCA 10.02.4 to 12.16.2, A8ns-M 10.03.2 to 14.19.4, A304 10.05.4 to 10.07.4, A3004NS-M,A5004NS-M,A9004M 10.05.4 to 14.19.4, N702R 10.05.8 to 10.06.8, A604M 10.06.4 to 10.07.2, A804NS-MU 10.06.4 to 12.10.2, N804R 10.06.4 to 12.16.2, A7004M,A8004T 10.06.8 to 14.19.4, A604G-MU 10.07.4 to 12.16.2, A3008-MU 10.08.4 to 14.19.4, A2004MU and A2004NS-MU 10.08.6 to 12.17.0, A604-V5,A604R, N702E 10.09.2 to 12.16.2, N2V 10.09.2 to 12.16.8, N604E 10.09.2 to 14.19.4, N104E 10.09.4 to 12.15.2, A8004ITL 11.00.4 to 14.19.4, N102E 11.00.8 to 12.15.2, N1V 11.01.2 to 12.07.6, N102i 11.01.2 to 12.15.2, T5004 11.96.4 to 14.19.4, N602E 11.96.6 to 12.16.8, AX8004BCM and A8004T-XR 11.97.2 to 14.19.4, A9004M-X2, T5008 11.98.2 to 14.19.4, N704E 11.98.4 to 12.16.2, A8004BCM 11.99.1 to 12.16.2, AX3004ITL 12.01.2 to 14.19.4 and A604G-skylife 12.02.4 to 12.12 were discovered to contain an OS command injection vulnerability via the function upnp_relay(). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-20T00:00:00.000Z
Updated: 2026-01-21T15:30:18.377Z
Reserved: 2025-08-13T00:00:00.000Z
Link: CVE-2025-55423
Updated: 2026-01-21T14:42:05.550Z
Status : Received
Published: 2026-01-20T18:16:04.810
Modified: 2026-01-21T15:16:06.457
Link: CVE-2025-55423
No data.