CVE-2025-55423

Exp

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.

Published: 2026-01-20 Last update: 2026-01-30 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-55423 is rated High Exploit Risk (79.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.66%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2025-55423

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2025-55423

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-22 0.56% 0.66% +0.11%
2 2026-03-03 0.50% 0.56% +0.06%
3 2026-01-31 0.50%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-55423

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2025-55423

Affected software / configurations for CVE-2025-55423

Vendor Product Version Raw CPE
iptime n104s-r1_firmware >= 9.90.8, <= 10.02.2 cpe:2.3:o:iptime:n104s-r1_firmware:*:*:*:*:*:*:*:*
iptime n104v_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n104v_firmware:*:*:*:*:*:*:*:*
iptime n1e_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n1e_firmware:*:*:*:*:*:*:*:*
iptime n1plus_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n1plus_firmware:*:*:*:*:*:*:*:*
iptime n1plus-i_firmware >= 9.99.6, <= 10.06.8 cpe:2.3:o:iptime:n1plus-i_firmware:*:*:*:*:*:*:*:*
iptime n1v_firmware >= 11.01.2, <= 12.07.6 cpe:2.3:o:iptime:n1v_firmware:*:*:*:*:*:*:*:*
iptime n2e_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n2e_firmware:*:*:*:*:*:*:*:*
iptime n2eplus_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n2eplus_firmware:*:*:*:*:*:*:*:*
iptime n2plus_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n2plus_firmware:*:*:*:*:*:*:*:*
iptime n2plus-i_firmware >= 9.99.6, <= 10.06.8 cpe:2.3:o:iptime:n2plus-i_firmware:*:*:*:*:*:*:*:*
iptime n2v_firmware >= 10.09.2, <= 12.16.8 cpe:2.3:o:iptime:n2v_firmware:*:*:*:*:*:*:*:*
iptime n2vs_firmware 12.16.8 cpe:2.3:o:iptime:n2vs_firmware:12.16.8:*:*:*:*:*:*:*
iptime n3_firmware >= 9.93.2, <= 10.06.8 cpe:2.3:o:iptime:n3_firmware:*:*:*:*:*:*:*:*
iptime n3-i_firmware >= 9.99.6, <= 10.06.8 cpe:2.3:o:iptime:n3-i_firmware:*:*:*:*:*:*:*:*
iptime n5_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n5_firmware:*:*:*:*:*:*:*:*
iptime n5-i_firmware >= 9.99.6, <= 10.06.8 cpe:2.3:o:iptime:n5-i_firmware:*:*:*:*:*:*:*:*
iptime n6_firmware >= 9.96.8, <= 10.06.8 cpe:2.3:o:iptime:n6_firmware:*:*:*:*:*:*:*:*
iptime n600_firmware >= 10.00.8, <= 12.16.2 cpe:2.3:o:iptime:n600_firmware:*:*:*:*:*:*:*:*
iptime n6004r_firmware >= 9.90.8, <= 10.02.2 cpe:2.3:o:iptime:n6004r_firmware:*:*:*:*:*:*:*:*
iptime n602e_firmware >= 11.96.6, <= 12.16.8 cpe:2.3:o:iptime:n602e_firmware:*:*:*:*:*:*:*:*
iptime n602eplus_firmware >= 12.14.2, <= 12.16.2 cpe:2.3:o:iptime:n602eplus_firmware:*:*:*:*:*:*:*:*
iptime n602se_firmware >= 14.19.0, <= 14.19.4 cpe:2.3:o:iptime:n602se_firmware:*:*:*:*:*:*:*:*
iptime n604_black_firmware >= 9.93.8, <= 12.16.2 cpe:2.3:o:iptime:n604_black_firmware:*:*:*:*:*:*:*:*
iptime n604a_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n604a_firmware:*:*:*:*:*:*:*:*
iptime n604e_firmware >= 10.09.2, <= 14.19.4 cpe:2.3:o:iptime:n604e_firmware:*:*:*:*:*:*:*:*
iptime n604eplus_firmware >= 12.14.2, <= 14.19.4 cpe:2.3:o:iptime:n604eplus_firmware:*:*:*:*:*:*:*:*
iptime n604plus_firmware >= 9.90.8, <= 12.15.2 cpe:2.3:o:iptime:n604plus_firmware:*:*:*:*:*:*:*:*
iptime n604plus-i_firmware >= 9.99.6, <= 12.14.6 cpe:2.3:o:iptime:n604plus-i_firmware:*:*:*:*:*:*:*:*
iptime n604r_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n604r_firmware:*:*:*:*:*:*:*:*
iptime n604rplus_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n604rplus_firmware:*:*:*:*:*:*:*:*
iptime n604rplus-i_firmware >= 9.99.6, <= 10.06.8 cpe:2.3:o:iptime:n604rplus-i_firmware:*:*:*:*:*:*:*:*
iptime n604s_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n604s_firmware:*:*:*:*:*:*:*:*
iptime n604se_firmware >= 14.18.4, <= 14.19.4 cpe:2.3:o:iptime:n604se_firmware:*:*:*:*:*:*:*:*
iptime n604t_firmware >= 9.90.8, <= 10.03.2 cpe:2.3:o:iptime:n604t_firmware:*:*:*:*:*:*:*:*
iptime n604tplus_firmware >= 9.90.8, <= 10.03.2 cpe:2.3:o:iptime:n604tplus_firmware:*:*:*:*:*:*:*:*
iptime n604v_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n604v_firmware:*:*:*:*:*:*:*:*
iptime n604vplus_firmware >= 9.90.8, <= 10.06.8 cpe:2.3:o:iptime:n604vplus_firmware:*:*:*:*:*:*:*:*
iptime n7004ns_firmware 9.91.2 cpe:2.3:o:iptime:n7004ns_firmware:9.91.2:*:*:*:*:*:*:*
iptime n702bcm_firmware >= 9.90.8, <= 12.16.2 cpe:2.3:o:iptime:n702bcm_firmware:*:*:*:*:*:*:*:*
iptime n702e_firmware >= 10.09.2, <= 12.16.2 cpe:2.3:o:iptime:n702e_firmware:*:*:*:*:*:*:*:*
iptime ax11000_firmware >= 14.16.6, <= 14.19.4 cpe:2.3:o:iptime:ax11000_firmware:*:*:*:*:*:*:*:*
iptime ax2002mesh_firmware >= 14.16.6, <= 14.19.4 cpe:2.3:o:iptime:ax2002mesh_firmware:*:*:*:*:*:*:*:*
iptime ax2004_firmware >= 14.17.4, <= 14.19.4 cpe:2.3:o:iptime:ax2004_firmware:*:*:*:*:*:*:*:*
iptime ax2004bcm_firmware >= 12.04.2, <= 14.19.4 cpe:2.3:o:iptime:ax2004bcm_firmware:*:*:*:*:*:*:*:*
iptime ax2004m_firmware >= 14.02.0, <= 14.19.4 cpe:2.3:o:iptime:ax2004m_firmware:*:*:*:*:*:*:*:*
iptime ax3004bcm_firmware >= 14.16.2, <= 14.19.4 cpe:2.3:o:iptime:ax3004bcm_firmware:*:*:*:*:*:*:*:*
iptime ax3004itl_firmware >= 12.01.2, <= 14.19.4 cpe:2.3:o:iptime:ax3004itl_firmware:*:*:*:*:*:*:*:*
iptime ax8004bcm_firmware >= 11.97.2, <= 14.19.4 cpe:2.3:o:iptime:ax8004bcm_firmware:*:*:*:*:*:*:*:*
iptime ax8004m_firmware >= 14.05.2, <= 14.19.4 cpe:2.3:o:iptime:ax8004m_firmware:*:*:*:*:*:*:*:*
iptime ax8008m_firmware >= 14.15.4, <= 14.19.4 cpe:2.3:o:iptime:ax8008m_firmware:*:*:*:*:*:*:*:*
iptime a1_firmware >= 9.96.8, <= 10.07.4 cpe:2.3:o:iptime:a1_firmware:*:*:*:*:*:*:*:*
iptime a1004_firmware >= 9.90.8, <= 12.16.2 cpe:2.3:o:iptime:a1004_firmware:*:*:*:*:*:*:*:*
iptime a1004ns_firmware >= 9.96.0, <= 12.16.2 cpe:2.3:o:iptime:a1004ns_firmware:*:*:*:*:*:*:*:*
iptime a1004v_firmware >= 9.90.8, <= 12.16.2 cpe:2.3:o:iptime:a1004v_firmware:*:*:*:*:*:*:*:*
iptime a104_firmware >= 9.90.8, <= 10.03.8 cpe:2.3:o:iptime:a104_firmware:*:*:*:*:*:*:*:*
iptime a104ns_firmware >= 9.96.0, <= 12.16.2 cpe:2.3:o:iptime:a104ns_firmware:*:*:*:*:*:*:*:*
iptime a104r_firmware >= 9.90.8, <= 10.07.4 cpe:2.3:o:iptime:a104r_firmware:*:*:*:*:*:*:*:*
iptime a104r_firmware cpe:2.3:o:iptime:a104r_firmware:-:*:*:*:*:*:*:*
iptime a2003mu_firmware >= 12.13.0, <= 12.16.2 cpe:2.3:o:iptime:a2003mu_firmware:*:*:*:*:*:*:*:*
iptime a2003ns-mu_firmware >= 10.00.6, <= 12.16.2 cpe:2.3:o:iptime:a2003ns-mu_firmware:*:*:*:*:*:*:*:*
iptime a2004_firmware >= 9.90.8, <= 10.07.4 cpe:2.3:o:iptime:a2004_firmware:*:*:*:*:*:*:*:*
iptime a2004mu_firmware >= 10.08.6, <= 12.17.0 cpe:2.3:o:iptime:a2004mu_firmware:*:*:*:*:*:*:*:*
iptime a2004ns_firmware >= 9.90.8, <= 11.00.4 cpe:2.3:o:iptime:a2004ns_firmware:*:*:*:*:*:*:*:*
iptime a2004ns-mu_firmware >= 10.08.6, <= 12.17.0 cpe:2.3:o:iptime:a2004ns-mu_firmware:*:*:*:*:*:*:*:*
iptime a2004ns-r_firmware >= 9.90.8, <= 11.00.4 cpe:2.3:o:iptime:a2004ns-r_firmware:*:*:*:*:*:*:*:*
iptime a2004nsplus_firmware >= 9.90.8, <= 11.00.4 cpe:2.3:o:iptime:a2004nsplus_firmware:*:*:*:*:*:*:*:*
iptime a2004plus_firmware >= 9.90.8, <= 10.07.4 cpe:2.3:o:iptime:a2004plus_firmware:*:*:*:*:*:*:*:*
iptime a2004r_firmware >= 9.90.8, <= 10.07.4 cpe:2.3:o:iptime:a2004r_firmware:*:*:*:*:*:*:*:*
iptime a2004se_firmware >= 14.16.6, <= 14.19.4 cpe:2.3:o:iptime:a2004se_firmware:*:*:*:*:*:*:*:*
iptime a2008_firmware >= 9.90.8, <= 10.07.4 cpe:2.3:o:iptime:a2008_firmware:*:*:*:*:*:*:*:*
iptime a3_firmware >= 9.97.2, <= 10.07.2 cpe:2.3:o:iptime:a3_firmware:*:*:*:*:*:*:*:*
iptime a3002mesh_firmware >= 12.05.4, <= 14.19.4 cpe:2.3:o:iptime:a3002mesh_firmware:*:*:*:*:*:*:*:*
iptime a3003ns_firmware >= 9.99.8, <= 11.00.4 cpe:2.3:o:iptime:a3003ns_firmware:*:*:*:*:*:*:*:*
iptime a3004_firmware >= 9.90.8, <= 10.08.2 cpe:2.3:o:iptime:a3004_firmware:*:*:*:*:*:*:*:*
iptime a3004-dual_firmware >= 9.90.4, <= 10.07.2 cpe:2.3:o:iptime:a3004-dual_firmware:*:*:*:*:*:*:*:*
iptime a3004m_firmware >= 14.18.4, <= 14.19.4 cpe:2.3:o:iptime:a3004m_firmware:*:*:*:*:*:*:*:*
iptime a3004ns_firmware >= 9.90.2, <= 10.09.4 cpe:2.3:o:iptime:a3004ns_firmware:*:*:*:*:*:*:*:*
iptime a3004ns-bcm_firmware >= 9.95.8, <= 11.00.4 cpe:2.3:o:iptime:a3004ns-bcm_firmware:*:*:*:*:*:*:*:*
iptime a3004ns-dual_firmware >= 9.90.4, <= 12.09.4 cpe:2.3:o:iptime:a3004ns-dual_firmware:*:*:*:*:*:*:*:*
iptime a3004ns-m_firmware >= 10.05.4, <= 14.19.4 cpe:2.3:o:iptime:a3004ns-m_firmware:*:*:*:*:*:*:*:*

References for CVE-2025-55423

cvelogic Threat Intelligence