CRITICAL · 9.8

CVE-2025-55423

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passe...

Vulnerability Description

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IptimeN104S-R1 Firmware>= 9.90.8, <= 10.02.2
IptimeN104S-R1-
IptimeN104V Firmware>= 9.90.8, <= 10.06.8
IptimeN104V-
IptimeN1E Firmware>= 9.90.8, <= 10.06.8
IptimeN1E-
IptimeN1Plus Firmware>= 9.90.8, <= 10.06.8
IptimeN1Plus-
IptimeN1Plus-I Firmware>= 9.99.6, <= 10.06.8
IptimeN1Plus-I-
IptimeN1V Firmware>= 11.01.2, <= 12.07.6
IptimeN1V-
IptimeN2E Firmware>= 9.90.8, <= 10.06.8
IptimeN2E-
IptimeN2Eplus Firmware>= 9.90.8, <= 10.06.8
IptimeN2Eplus-
IptimeN2Plus Firmware>= 9.90.8, <= 10.06.8
IptimeN2Plus-
IptimeN2Plus-I Firmware>= 9.99.6, <= 10.06.8
IptimeN2Plus-I-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-55423?

CVE-2025-55423 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passe...

How severe is CVE-2025-55423?

CVE-2025-55423 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-55423?

Check the references section above for vendor advisories and patch information. Affected products include: Iptime N104S-R1 Firmware, Iptime N104S-R1, Iptime N104V Firmware, Iptime N104V, Iptime N1E Firmware.