9.8

CVE-2025-55423

Exploit
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IptimeN104s-r1 Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN104s-r1 Version-
IptimeN104v Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN104v Version-
IptimeN1e Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN1e Version-
IptimeN1plus Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN1plus Version-
IptimeN1plus-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN1plus-i Version-
IptimeN1v Firmware Version >= 11.01.2 <= 12.07.6
   IptimeN1v Version-
IptimeN2e Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN2e Version-
IptimeN2eplus Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN2eplus Version-
IptimeN2plus Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN2plus Version-
IptimeN2plus-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN2plus-i Version-
IptimeN2v Firmware Version >= 10.09.2 <= 12.16.8
   IptimeN2v Version-
IptimeN2vs Firmware Version12.16.8
   IptimeN2vs Version-
IptimeN3 Firmware Version >= 9.93.2 <= 10.06.8
   IptimeN3 Version-
IptimeN3-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN3-i Version-
IptimeN5 Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN5 Version-
IptimeN5-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN5-i Version-
IptimeN6 Firmware Version >= 9.96.8 <= 10.06.8
   IptimeN6 Version-
IptimeN600 Firmware Version >= 10.00.8 <= 12.16.2
   IptimeN600 Version-
IptimeN6004r Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN6004r Version-
IptimeN602e Firmware Version >= 11.96.6 <= 12.16.8
   IptimeN602e Version-
IptimeN602eplus Firmware Version >= 12.14.2 <= 12.16.2
   IptimeN602eplus Version-
IptimeN602se Firmware Version >= 14.19.0 <= 14.19.4
   IptimeN602se Version-
IptimeN604 Black Firmware Version >= 9.93.8 <= 12.16.2
   IptimeN604 Black Version-
IptimeN604a Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN604a Version-
IptimeN604e Firmware Version >= 10.09.2 <= 14.19.4
   IptimeN604e Version-
IptimeN604eplus Firmware Version >= 12.14.2 <= 14.19.4
   IptimeN604eplus Version-
IptimeN604plus Firmware Version >= 9.90.8 <= 12.15.2
   IptimeN604plus Version-
IptimeN604plus-i Firmware Version >= 9.99.6 <= 12.14.6
   IptimeN604plus-i Version-
IptimeN604r Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN604r Version-
IptimeN604rplus Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN604rplus Version-
IptimeN604rplus-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN604rplus-i Version-
IptimeN604s Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN604s Version-
IptimeN604se Firmware Version >= 14.18.4 <= 14.19.4
   IptimeN604se Version-
IptimeN604t Firmware Version >= 9.90.8 <= 10.03.2
   IptimeN604t Version-
IptimeN604tplus Firmware Version >= 9.90.8 <= 10.03.2
   IptimeN604tplus Version-
IptimeN604v Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN604v Version-
IptimeN604vplus Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN604vplus Version-
IptimeN7004ns Firmware Version9.91.2
   IptimeN7004ns Version-
IptimeN702bcm Firmware Version >= 9.90.8 <= 12.16.2
   IptimeN702bcm Version-
IptimeN702e Firmware Version >= 10.09.2 <= 12.16.2
   IptimeN702e Version-
IptimeAx11000 Firmware Version >= 14.16.6 <= 14.19.4
   IptimeAx11000 Version-
IptimeAx2002mesh Firmware Version >= 14.16.6 <= 14.19.4
   IptimeAx2002mesh Version-
IptimeAx2004 Firmware Version >= 14.17.4 <= 14.19.4
   IptimeAx2004 Version-
IptimeAx2004bcm Firmware Version >= 12.04.2 <= 14.19.4
   IptimeAx2004bcm Version-
IptimeAx2004m Firmware Version >= 14.02.0 <= 14.19.4
   IptimeAx2004m Version-
IptimeAx3004bcm Firmware Version >= 14.16.2 <= 14.19.4
   IptimeAx3004bcm Version-
IptimeAx3004itl Firmware Version >= 12.01.2 <= 14.19.4
   IptimeAx3004itl Version-
IptimeAx8004bcm Firmware Version >= 11.97.2 <= 14.19.4
   IptimeAx8004bcm Version-
IptimeAx8004m Firmware Version >= 14.05.2 <= 14.19.4
   IptimeAx8004m Version-
IptimeAx8008m Firmware Version >= 14.15.4 <= 14.19.4
   IptimeAx8008m Version-
IptimeA1 Firmware Version >= 9.96.8 <= 10.07.4
   IptimeA1 Version-
IptimeA1004 Firmware Version >= 9.90.8 <= 12.16.2
   IptimeA1004 Version-
IptimeA1004ns Firmware Version >= 9.96.0 <= 12.16.2
   IptimeA1004ns Version-
IptimeA1004v Firmware Version >= 9.90.8 <= 12.16.2
   IptimeA1004v Version-
IptimeA104 Firmware Version >= 9.90.8 <= 10.03.8
   IptimeA104 Version-
IptimeA104ns Firmware Version >= 9.96.0 <= 12.16.2
   IptimeA104ns Version-
IptimeA104r Firmware Version >= 9.90.8 <= 10.07.4
   IptimeA104r Version-
IptimeA104r Firmware Version-
   IptimeA104r Version-
IptimeA2003mu Firmware Version >= 12.13.0 <= 12.16.2
   IptimeA2003mu Version-
IptimeA2003ns-mu Firmware Version >= 10.00.6 <= 12.16.2
   IptimeA2003ns-mu Version-
IptimeA2004 Firmware Version >= 9.90.8 <= 10.07.4
   IptimeA2004 Version-
IptimeA2004mu Firmware Version >= 10.08.6 <= 12.17.0
   IptimeA2004mu Version-
IptimeA2004ns Firmware Version >= 9.90.8 <= 11.00.4
   IptimeA2004ns Version-
IptimeA2004ns-mu Firmware Version >= 10.08.6 <= 12.17.0
   IptimeA2004ns-mu Version-
IptimeA2004ns-r Firmware Version >= 9.90.8 <= 11.00.4
   IptimeA2004ns-r Version-
IptimeA2004nsplus Firmware Version >= 9.90.8 <= 11.00.4
   IptimeA2004nsplus Version-
IptimeA2004plus Firmware Version >= 9.90.8 <= 10.07.4
   IptimeA2004plus Version-
IptimeA2004r Firmware Version >= 9.90.8 <= 10.07.4
   IptimeA2004r Version-
IptimeA2004se Firmware Version >= 14.16.6 <= 14.19.4
   IptimeA2004se Version-
IptimeA2008 Firmware Version >= 9.90.8 <= 10.07.4
   IptimeA2008 Version-
IptimeA3 Firmware Version >= 9.97.2 <= 10.07.2
   IptimeA3 Version-
IptimeA3002mesh Firmware Version >= 12.05.4 <= 14.19.4
   IptimeA3002mesh Version-
IptimeA3003ns Firmware Version >= 9.99.8 <= 11.00.4
   IptimeA3003ns Version-
IptimeA3004 Firmware Version >= 9.90.8 <= 10.08.2
   IptimeA3004 Version-
IptimeA3004-dual Firmware Version >= 9.90.4 <= 10.07.2
   IptimeA3004-dual Version-
IptimeA3004m Firmware Version >= 14.18.4 <= 14.19.4
   IptimeA3004m Version-
IptimeA3004ns Firmware Version >= 9.90.2 <= 10.09.4
   IptimeA3004ns Version-
IptimeA3004ns-bcm Firmware Version >= 9.95.8 <= 11.00.4
   IptimeA3004ns-bcm Version-
IptimeA3004ns-dual Firmware Version >= 9.90.4 <= 12.09.4
   IptimeA3004ns-dual Version-
IptimeA3004ns-m Firmware Version >= 10.05.4 <= 14.19.4
   IptimeA3004ns-m Version-
IptimeA3004t Firmware Version >= 12.10.2 <= 14.19.4
   IptimeA3004t Version-
IptimeA3004tw Firmware Version >= 14.15.2 <= 14.19.4
   IptimeA3004tw Version-
IptimeA3008-mu Firmware Version >= 10.08.4 <= 14.19.4
   IptimeA3008-mu Version-
IptimeA304 Firmware Version >= 10.05.4 <= 10.07.4
   IptimeA304 Version-
IptimeA5004ns Firmware Version >= 9.90.2 <= 11.00.4
   IptimeA5004ns Version-
IptimeA5004ns-m Firmware Version >= 10.05.4 <= 14.19.4
   IptimeA5004ns-m Version-
IptimeA6004mx Firmware Version >= 12.04.6 <= 14.19.4
   IptimeA6004mx Version-
IptimeA6004ns Firmware Version >= 9.90.2 <= 11.00.4
   IptimeA6004ns Version-
IptimeA6004ns-m Firmware Version >= 9.99.8 <= 14.19.4
   IptimeA6004ns-m Version-
IptimeA604 Firmware Version >= 9.90.8 <= 12.06.6
   IptimeA604 Version-
IptimeA604-v3 Firmware Version >= 10.01.6 <= 10.07.2
   IptimeA604-v3 Version-
IptimeA604-v5 Firmware Version >= 10.09.2 <= 12.16.2
   IptimeA604-v5 Version-
IptimeA604g-mu Firmware Version >= 10.07.4 <= 12.16.2
   IptimeA604g-mu Version-
IptimeA604g-skylife Firmware Version >= 12.02.4 <= 12.12.4
   IptimeA604g-skylife Version-
IptimeA604m Firmware Version >= 10.06.4 <= 10.07.2
   IptimeA604m Version-
IptimeA604mu Firmware Version >= 12.12.4 <= 12.16.2
   IptimeA604mu Version-
IptimeA604r Firmware Version >= 10.09.2 <= 12.16.2
   IptimeA604r Version-
IptimeA604se Firmware Version >= 14.17.2 <= 14.19.4
   IptimeA604se Version-
IptimeA604v Firmware Version >= 9.90.8 <= 10.07.4
   IptimeA604v Version-
IptimeA6ns-m Firmware Version >= 10.01.6 <= 14.19.4
   IptimeA6ns-m Version-
IptimeA7004m Firmware Version >= 10.06.8 <= 14.19.4
   IptimeA7004m Version-
IptimeA704ns-bcm Firmware Version >= 9.95.8 <= 11.00.4
   IptimeA704ns-bcm Version-
IptimeA7ns Firmware Version >= 9.96.0 <= 11.00.4
   IptimeA7ns Version-
IptimeA8004bcm Firmware Version >= 11.99.1 <= 12.16.2
   IptimeA8004bcm Version-
IptimeA8004itl Firmware Version >= 11.00.4 <= 14.19.4
   IptimeA8004itl Version-
IptimeA8004ns-m Firmware Version >= 9.99.2 <= 14.19.4
   IptimeA8004ns-m Version-
IptimeA8004t Firmware Version >= 10.06.8 <= 14.19.4
   IptimeA8004t Version-
IptimeA8004t-xr Firmware Version >= 11.97.2 <= 14.19.4
   IptimeA8004t-xr Version-
IptimeA804ns-mu Firmware Version >= 10.06.4 <= 12.10.2
   IptimeA804ns-mu Version-
IptimeA8ns-m Firmware Version >= 10.03.2 <= 14.19.4
   IptimeA8ns-m Version-
IptimeA9004m Firmware Version >= 10.05.4 <= 14.19.4
   IptimeA9004m Version-
IptimeA9004m-x2 Firmware Version >= 11.98.2 <= 14.19.4
   IptimeA9004m-x2 Version-
IptimeEw302n Firmware Version >= 9.90.8 <= 12.16.2
   IptimeEw302n Version-
IptimeN102e Firmware Version >= 11.00.8 <= 12.15.2
   IptimeN102e Version-
IptimeN102eplus Firmware Version >= 12.14.2 <= 12.15.2
   IptimeN102eplus Version-
IptimeN102i Firmware Version >= 11.01.2 <= 12.15.2
   IptimeN102i Version-
IptimeN102iplus Firmware Version >= 12.14.2 <= 12.15.2
   IptimeN102iplus Version-
IptimeN104 Black Firmware Version >= 9.93.8 <= 10.06.8
   IptimeN104 Black Version-
IptimeN104e Firmware Version >= 10.09.4 <= 12.15.2
   IptimeN104e Version-
IptimeN104eplus Firmware Version >= 12.14.2 <= 12.15.2
   IptimeN104eplus Version-
IptimeN104k Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN104k Version-
IptimeN104plus Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN104plus Version-
IptimeN104plus-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN104plus-i Version-
IptimeN104q Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN104q Version-
IptimeN104q-i Firmware Version >= 9.99.6 <= 10.06.8
   IptimeN104q-i Version-
IptimeN104r Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN104r Version-
IptimeN702eplus Firmware Version >= 12.12.4 <= 12.16.2
   IptimeN702eplus Version-
IptimeN702r Firmware Version >= 10.05.8 <= 10.06.8
   IptimeN702r Version-
IptimeN704-a3 Firmware Version >= 9.90.8 <= 10.06.8
   IptimeN704-a3 Version-
IptimeN704bcm Firmware Version >= 9.90.8 <= 12.16.2
   IptimeN704bcm Version-
IptimeN704e Firmware Version >= 11.98.4 <= 12.16.2
   IptimeN704e Version-
IptimeN704eplus Firmware Version >= 12.14.2 <= 12.16.2
   IptimeN704eplus Version-
IptimeN704ns Firmware Version >= 9.91.4 <= 9.96.0
   IptimeN704ns Version-
IptimeN704qca Firmware Version >= 10.02.4 <= 12.16.2
   IptimeN704qca Version-
IptimeN704v3 Firmware Version >= 9.90.8 <= 12.10.2
   IptimeN704v3 Version-
IptimeN8004r Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN8004r Version-
IptimeN8004v Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN8004v Version-
IptimeN804 Firmware Version >= 9.91.2 <= 9.96.8
   IptimeN804 Version-
IptimeN804a Firmware Version >= 9.91.2 <= 9.96.8
   IptimeN804a Version-
IptimeN804a3 Firmware Version >= 9.90.8 <= 9.96.8
   IptimeN804a3 Version-
IptimeN804r Firmware Version >= 10.06.4 <= 12.16.2
   IptimeN804r Version-
IptimeN804t Firmware Version >= 9.91.2 <= 9.96.8
   IptimeN804t Version-
IptimeN804t3 Firmware Version >= 9.90.8 <= 9.96.8
   IptimeN804t3 Version-
IptimeN804v Firmware Version >= 9.91.2 <= 9.96.8
   IptimeN804v Version-
IptimeN904 Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN904 Version-
IptimeN904ns Firmware Version >= 9.91.4 <= 9.96.0
   IptimeN904ns Version-
IptimeN904plus Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN904plus Version-
IptimeN904v Firmware Version >= 9.90.8 <= 10.02.2
   IptimeN904v Version-
IptimeSmart Firmware Version >= 9.90.8 <= 9.94.2
   IptimeSmart Version-
IptimeQ1 Firmware Version9.91.2
   IptimeQ1 Version-
IptimeQ304 Firmware Version9.91.2
   IptimeQ304 Version-
IptimeQ504 Firmware Version9.91.2
   IptimeQ504 Version-
IptimeQ604 Firmware Version9.91.2
   IptimeQ604 Version-
IptimeT16000 Firmware Version >= 9.91.2 <= 11.03.6
   IptimeT16000 Version-
IptimeT16000m Firmware Version >= 12.07.4 <= 14.19.4
   IptimeT16000m Version-
IptimeT24000 Firmware Version >= 9.91.2 <= 11.03.6
   IptimeT24000 Version-
IptimeT24000m Firmware Version >= 12.07.4 <= 14.19.4
   IptimeT24000m Version-
IptimeT3004 Firmware Version >= 9.90.8 <= 12.07.6
   IptimeT3004 Version-
IptimeT3008 Firmware Version >= 9.90.8 <= 12.09.6
   IptimeT3008 Version-
IptimeT5004 Firmware Version >= 11.96.4 <= 14.19.4
   IptimeT5004 Version-
IptimeT5008 Firmware Version >= 11.98.2 <= 14.19.4
   IptimeT5008 Version-
IptimeV304 Firmware Version9.91.2
   IptimeV304 Version-
IptimeV504 Firmware Version >= 9.90.8 <= 12.15.2
   IptimeV504 Version-
IptimeV508 Firmware Version >= 10.02.2 <= 10.06.4
   IptimeV508 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.