A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
History

Wed, 21 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Description ipTIME routers A2003NS-MU 10.00.6 to 12.16.2 , N600 10.00.8 to 12.16.2, A604-V3 10.01.6 to 10.07.2, A6ns-M 10.01.6 to 14.19.4 , V508 10.02.2 to 10.06.4, N704QCA 10.02.4 to 12.16.2, A8ns-M 10.03.2 to 14.19.4, A304 10.05.4 to 10.07.4, A3004NS-M,A5004NS-M,A9004M 10.05.4 to 14.19.4, N702R 10.05.8 to 10.06.8, A604M 10.06.4 to 10.07.2, A804NS-MU 10.06.4 to 12.10.2, N804R 10.06.4 to 12.16.2, A7004M,A8004T 10.06.8 to 14.19.4, A604G-MU 10.07.4 to 12.16.2, A3008-MU 10.08.4 to 14.19.4, A2004MU and A2004NS-MU 10.08.6 to 12.17.0, A604-V5,A604R, N702E 10.09.2 to 12.16.2, N2V 10.09.2 to 12.16.8, N604E 10.09.2 to 14.19.4, N104E 10.09.4 to 12.15.2, A8004ITL 11.00.4 to 14.19.4, N102E 11.00.8 to 12.15.2, N1V 11.01.2 to 12.07.6, N102i 11.01.2 to 12.15.2, T5004 11.96.4 to 14.19.4, N602E 11.96.6 to 12.16.8, AX8004BCM and A8004T-XR 11.97.2 to 14.19.4, A9004M-X2, T5008 11.98.2 to 14.19.4, N704E 11.98.4 to 12.16.2, A8004BCM 11.99.1 to 12.16.2, AX3004ITL 12.01.2 to 14.19.4 and A604G-skylife 12.02.4 to 12.12 were discovered to contain an OS command injection vulnerability via the function upnp_relay(). A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 Jan 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Iptime
Iptime a2003ns-mu
Iptime a2004mu
Iptime a2004ns-mu
Iptime a3004ns-m
Iptime a3008-mu
Iptime a304
Iptime a5004ns-m
Iptime a604-v3
Iptime a604-v5
Iptime a604g-mu
Iptime a604g-skylife
Iptime a604m
Iptime a604r
Iptime a6ns-m
Iptime a7004m
Iptime a8004bcm
Iptime a8004itl
Iptime a8004t
Iptime a8004t-xr
Iptime a804ns-mu
Iptime a8ns-m
Iptime a9004m
Iptime a9004m-x2
Iptime ax3004itl
Iptime ax8004bcm
Iptime n102e
Iptime n102i
Iptime n104e
Iptime n1v
Iptime n2v
Iptime n600
Iptime n602e
Iptime n604e
Iptime n702e
Iptime n702r
Iptime n704e
Iptime n704qca
Iptime n804r
Iptime t5004
Iptime t5008
Iptime v508
Vendors & Products Iptime
Iptime a2003ns-mu
Iptime a2004mu
Iptime a2004ns-mu
Iptime a3004ns-m
Iptime a3008-mu
Iptime a304
Iptime a5004ns-m
Iptime a604-v3
Iptime a604-v5
Iptime a604g-mu
Iptime a604g-skylife
Iptime a604m
Iptime a604r
Iptime a6ns-m
Iptime a7004m
Iptime a8004bcm
Iptime a8004itl
Iptime a8004t
Iptime a8004t-xr
Iptime a804ns-mu
Iptime a8ns-m
Iptime a9004m
Iptime a9004m-x2
Iptime ax3004itl
Iptime ax8004bcm
Iptime n102e
Iptime n102i
Iptime n104e
Iptime n1v
Iptime n2v
Iptime n600
Iptime n602e
Iptime n604e
Iptime n702e
Iptime n702r
Iptime n704e
Iptime n704qca
Iptime n804r
Iptime t5004
Iptime t5008
Iptime v508

Tue, 20 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description ipTIME routers A2003NS-MU 10.00.6 to 12.16.2 , N600 10.00.8 to 12.16.2, A604-V3 10.01.6 to 10.07.2, A6ns-M 10.01.6 to 14.19.4 , V508 10.02.2 to 10.06.4, N704QCA 10.02.4 to 12.16.2, A8ns-M 10.03.2 to 14.19.4, A304 10.05.4 to 10.07.4, A3004NS-M,A5004NS-M,A9004M 10.05.4 to 14.19.4, N702R 10.05.8 to 10.06.8, A604M 10.06.4 to 10.07.2, A804NS-MU 10.06.4 to 12.10.2, N804R 10.06.4 to 12.16.2, A7004M,A8004T 10.06.8 to 14.19.4, A604G-MU 10.07.4 to 12.16.2, A3008-MU 10.08.4 to 14.19.4, A2004MU and A2004NS-MU 10.08.6 to 12.17.0, A604-V5,A604R, N702E 10.09.2 to 12.16.2, N2V 10.09.2 to 12.16.8, N604E 10.09.2 to 14.19.4, N104E 10.09.4 to 12.15.2, A8004ITL 11.00.4 to 14.19.4, N102E 11.00.8 to 12.15.2, N1V 11.01.2 to 12.07.6, N102i 11.01.2 to 12.15.2, T5004 11.96.4 to 14.19.4, N602E 11.96.6 to 12.16.8, AX8004BCM and A8004T-XR 11.97.2 to 14.19.4, A9004M-X2, T5008 11.98.2 to 14.19.4, N704E 11.98.4 to 12.16.2, A8004BCM 11.99.1 to 12.16.2, AX3004ITL 12.01.2 to 14.19.4 and A604G-skylife 12.02.4 to 12.12 were discovered to contain an OS command injection vulnerability via the function upnp_relay().
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-01-20T00:00:00.000Z

Updated: 2026-01-21T15:30:18.377Z

Reserved: 2025-08-13T00:00:00.000Z

Link: CVE-2025-55423

cve-icon Vulnrichment

Updated: 2026-01-21T14:42:05.550Z

cve-icon NVD

Status : Received

Published: 2026-01-20T18:16:04.810

Modified: 2026-01-21T15:16:06.457

Link: CVE-2025-55423

cve-icon Redhat

No data.