A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Conclusion & alert: CVE-2025-55423 is rated High Exploit Risk (79.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.66%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.56% | 0.66% | +0.11% |
| 2 | 2026-03-03 | 0.50% | 0.56% | +0.06% |
| 3 | 2026-01-31 | — | 0.50% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| iptime | n104s-r1_firmware | >= 9.90.8, <= 10.02.2 | cpe:2.3:o:iptime:n104s-r1_firmware:*:*:*:*:*:*:*:* |
| iptime | n104v_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n104v_firmware:*:*:*:*:*:*:*:* |
| iptime | n1e_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n1e_firmware:*:*:*:*:*:*:*:* |
| iptime | n1plus_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n1plus_firmware:*:*:*:*:*:*:*:* |
| iptime | n1plus-i_firmware | >= 9.99.6, <= 10.06.8 | cpe:2.3:o:iptime:n1plus-i_firmware:*:*:*:*:*:*:*:* |
| iptime | n1v_firmware | >= 11.01.2, <= 12.07.6 | cpe:2.3:o:iptime:n1v_firmware:*:*:*:*:*:*:*:* |
| iptime | n2e_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n2e_firmware:*:*:*:*:*:*:*:* |
| iptime | n2eplus_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n2eplus_firmware:*:*:*:*:*:*:*:* |
| iptime | n2plus_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n2plus_firmware:*:*:*:*:*:*:*:* |
| iptime | n2plus-i_firmware | >= 9.99.6, <= 10.06.8 | cpe:2.3:o:iptime:n2plus-i_firmware:*:*:*:*:*:*:*:* |
| iptime | n2v_firmware | >= 10.09.2, <= 12.16.8 | cpe:2.3:o:iptime:n2v_firmware:*:*:*:*:*:*:*:* |
| iptime | n2vs_firmware | 12.16.8 | cpe:2.3:o:iptime:n2vs_firmware:12.16.8:*:*:*:*:*:*:* |
| iptime | n3_firmware | >= 9.93.2, <= 10.06.8 | cpe:2.3:o:iptime:n3_firmware:*:*:*:*:*:*:*:* |
| iptime | n3-i_firmware | >= 9.99.6, <= 10.06.8 | cpe:2.3:o:iptime:n3-i_firmware:*:*:*:*:*:*:*:* |
| iptime | n5_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n5_firmware:*:*:*:*:*:*:*:* |
| iptime | n5-i_firmware | >= 9.99.6, <= 10.06.8 | cpe:2.3:o:iptime:n5-i_firmware:*:*:*:*:*:*:*:* |
| iptime | n6_firmware | >= 9.96.8, <= 10.06.8 | cpe:2.3:o:iptime:n6_firmware:*:*:*:*:*:*:*:* |
| iptime | n600_firmware | >= 10.00.8, <= 12.16.2 | cpe:2.3:o:iptime:n600_firmware:*:*:*:*:*:*:*:* |
| iptime | n6004r_firmware | >= 9.90.8, <= 10.02.2 | cpe:2.3:o:iptime:n6004r_firmware:*:*:*:*:*:*:*:* |
| iptime | n602e_firmware | >= 11.96.6, <= 12.16.8 | cpe:2.3:o:iptime:n602e_firmware:*:*:*:*:*:*:*:* |
| iptime | n602eplus_firmware | >= 12.14.2, <= 12.16.2 | cpe:2.3:o:iptime:n602eplus_firmware:*:*:*:*:*:*:*:* |
| iptime | n602se_firmware | >= 14.19.0, <= 14.19.4 | cpe:2.3:o:iptime:n602se_firmware:*:*:*:*:*:*:*:* |
| iptime | n604_black_firmware | >= 9.93.8, <= 12.16.2 | cpe:2.3:o:iptime:n604_black_firmware:*:*:*:*:*:*:*:* |
| iptime | n604a_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n604a_firmware:*:*:*:*:*:*:*:* |
| iptime | n604e_firmware | >= 10.09.2, <= 14.19.4 | cpe:2.3:o:iptime:n604e_firmware:*:*:*:*:*:*:*:* |
| iptime | n604eplus_firmware | >= 12.14.2, <= 14.19.4 | cpe:2.3:o:iptime:n604eplus_firmware:*:*:*:*:*:*:*:* |
| iptime | n604plus_firmware | >= 9.90.8, <= 12.15.2 | cpe:2.3:o:iptime:n604plus_firmware:*:*:*:*:*:*:*:* |
| iptime | n604plus-i_firmware | >= 9.99.6, <= 12.14.6 | cpe:2.3:o:iptime:n604plus-i_firmware:*:*:*:*:*:*:*:* |
| iptime | n604r_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n604r_firmware:*:*:*:*:*:*:*:* |
| iptime | n604rplus_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n604rplus_firmware:*:*:*:*:*:*:*:* |
| iptime | n604rplus-i_firmware | >= 9.99.6, <= 10.06.8 | cpe:2.3:o:iptime:n604rplus-i_firmware:*:*:*:*:*:*:*:* |
| iptime | n604s_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n604s_firmware:*:*:*:*:*:*:*:* |
| iptime | n604se_firmware | >= 14.18.4, <= 14.19.4 | cpe:2.3:o:iptime:n604se_firmware:*:*:*:*:*:*:*:* |
| iptime | n604t_firmware | >= 9.90.8, <= 10.03.2 | cpe:2.3:o:iptime:n604t_firmware:*:*:*:*:*:*:*:* |
| iptime | n604tplus_firmware | >= 9.90.8, <= 10.03.2 | cpe:2.3:o:iptime:n604tplus_firmware:*:*:*:*:*:*:*:* |
| iptime | n604v_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n604v_firmware:*:*:*:*:*:*:*:* |
| iptime | n604vplus_firmware | >= 9.90.8, <= 10.06.8 | cpe:2.3:o:iptime:n604vplus_firmware:*:*:*:*:*:*:*:* |
| iptime | n7004ns_firmware | 9.91.2 | cpe:2.3:o:iptime:n7004ns_firmware:9.91.2:*:*:*:*:*:*:* |
| iptime | n702bcm_firmware | >= 9.90.8, <= 12.16.2 | cpe:2.3:o:iptime:n702bcm_firmware:*:*:*:*:*:*:*:* |
| iptime | n702e_firmware | >= 10.09.2, <= 12.16.2 | cpe:2.3:o:iptime:n702e_firmware:*:*:*:*:*:*:*:* |
| iptime | ax11000_firmware | >= 14.16.6, <= 14.19.4 | cpe:2.3:o:iptime:ax11000_firmware:*:*:*:*:*:*:*:* |
| iptime | ax2002mesh_firmware | >= 14.16.6, <= 14.19.4 | cpe:2.3:o:iptime:ax2002mesh_firmware:*:*:*:*:*:*:*:* |
| iptime | ax2004_firmware | >= 14.17.4, <= 14.19.4 | cpe:2.3:o:iptime:ax2004_firmware:*:*:*:*:*:*:*:* |
| iptime | ax2004bcm_firmware | >= 12.04.2, <= 14.19.4 | cpe:2.3:o:iptime:ax2004bcm_firmware:*:*:*:*:*:*:*:* |
| iptime | ax2004m_firmware | >= 14.02.0, <= 14.19.4 | cpe:2.3:o:iptime:ax2004m_firmware:*:*:*:*:*:*:*:* |
| iptime | ax3004bcm_firmware | >= 14.16.2, <= 14.19.4 | cpe:2.3:o:iptime:ax3004bcm_firmware:*:*:*:*:*:*:*:* |
| iptime | ax3004itl_firmware | >= 12.01.2, <= 14.19.4 | cpe:2.3:o:iptime:ax3004itl_firmware:*:*:*:*:*:*:*:* |
| iptime | ax8004bcm_firmware | >= 11.97.2, <= 14.19.4 | cpe:2.3:o:iptime:ax8004bcm_firmware:*:*:*:*:*:*:*:* |
| iptime | ax8004m_firmware | >= 14.05.2, <= 14.19.4 | cpe:2.3:o:iptime:ax8004m_firmware:*:*:*:*:*:*:*:* |
| iptime | ax8008m_firmware | >= 14.15.4, <= 14.19.4 | cpe:2.3:o:iptime:ax8008m_firmware:*:*:*:*:*:*:*:* |
| iptime | a1_firmware | >= 9.96.8, <= 10.07.4 | cpe:2.3:o:iptime:a1_firmware:*:*:*:*:*:*:*:* |
| iptime | a1004_firmware | >= 9.90.8, <= 12.16.2 | cpe:2.3:o:iptime:a1004_firmware:*:*:*:*:*:*:*:* |
| iptime | a1004ns_firmware | >= 9.96.0, <= 12.16.2 | cpe:2.3:o:iptime:a1004ns_firmware:*:*:*:*:*:*:*:* |
| iptime | a1004v_firmware | >= 9.90.8, <= 12.16.2 | cpe:2.3:o:iptime:a1004v_firmware:*:*:*:*:*:*:*:* |
| iptime | a104_firmware | >= 9.90.8, <= 10.03.8 | cpe:2.3:o:iptime:a104_firmware:*:*:*:*:*:*:*:* |
| iptime | a104ns_firmware | >= 9.96.0, <= 12.16.2 | cpe:2.3:o:iptime:a104ns_firmware:*:*:*:*:*:*:*:* |
| iptime | a104r_firmware | >= 9.90.8, <= 10.07.4 | cpe:2.3:o:iptime:a104r_firmware:*:*:*:*:*:*:*:* |
| iptime | a104r_firmware | — | cpe:2.3:o:iptime:a104r_firmware:-:*:*:*:*:*:*:* |
| iptime | a2003mu_firmware | >= 12.13.0, <= 12.16.2 | cpe:2.3:o:iptime:a2003mu_firmware:*:*:*:*:*:*:*:* |
| iptime | a2003ns-mu_firmware | >= 10.00.6, <= 12.16.2 | cpe:2.3:o:iptime:a2003ns-mu_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004_firmware | >= 9.90.8, <= 10.07.4 | cpe:2.3:o:iptime:a2004_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004mu_firmware | >= 10.08.6, <= 12.17.0 | cpe:2.3:o:iptime:a2004mu_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004ns_firmware | >= 9.90.8, <= 11.00.4 | cpe:2.3:o:iptime:a2004ns_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004ns-mu_firmware | >= 10.08.6, <= 12.17.0 | cpe:2.3:o:iptime:a2004ns-mu_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004ns-r_firmware | >= 9.90.8, <= 11.00.4 | cpe:2.3:o:iptime:a2004ns-r_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004nsplus_firmware | >= 9.90.8, <= 11.00.4 | cpe:2.3:o:iptime:a2004nsplus_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004plus_firmware | >= 9.90.8, <= 10.07.4 | cpe:2.3:o:iptime:a2004plus_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004r_firmware | >= 9.90.8, <= 10.07.4 | cpe:2.3:o:iptime:a2004r_firmware:*:*:*:*:*:*:*:* |
| iptime | a2004se_firmware | >= 14.16.6, <= 14.19.4 | cpe:2.3:o:iptime:a2004se_firmware:*:*:*:*:*:*:*:* |
| iptime | a2008_firmware | >= 9.90.8, <= 10.07.4 | cpe:2.3:o:iptime:a2008_firmware:*:*:*:*:*:*:*:* |
| iptime | a3_firmware | >= 9.97.2, <= 10.07.2 | cpe:2.3:o:iptime:a3_firmware:*:*:*:*:*:*:*:* |
| iptime | a3002mesh_firmware | >= 12.05.4, <= 14.19.4 | cpe:2.3:o:iptime:a3002mesh_firmware:*:*:*:*:*:*:*:* |
| iptime | a3003ns_firmware | >= 9.99.8, <= 11.00.4 | cpe:2.3:o:iptime:a3003ns_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004_firmware | >= 9.90.8, <= 10.08.2 | cpe:2.3:o:iptime:a3004_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004-dual_firmware | >= 9.90.4, <= 10.07.2 | cpe:2.3:o:iptime:a3004-dual_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004m_firmware | >= 14.18.4, <= 14.19.4 | cpe:2.3:o:iptime:a3004m_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004ns_firmware | >= 9.90.2, <= 10.09.4 | cpe:2.3:o:iptime:a3004ns_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004ns-bcm_firmware | >= 9.95.8, <= 11.00.4 | cpe:2.3:o:iptime:a3004ns-bcm_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004ns-dual_firmware | >= 9.90.4, <= 12.09.4 | cpe:2.3:o:iptime:a3004ns-dual_firmware:*:*:*:*:*:*:*:* |
| iptime | a3004ns-m_firmware | >= 10.05.4, <= 14.19.4 | cpe:2.3:o:iptime:a3004ns-m_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://docs.google.com/spreadsheets/d/1kryOFltCmnPJvDTpIrudgryt79uI4PWchuQ8-Gak24c/edit?usp=sharing | Third Party Advisory |
| https://github.com/0x0xxxx/CVE/blob/main/CVE-2025-55423/README.md | Exploit Third Party Advisory |
| https://github.com/0x0xxxx/CVE/blob/main/CVE-2025-55423/assets/affected_products_cve_format.json | Third Party Advisory |
| https://iptime.com/iptime/?pageid=4&page_id=126&dfsid=3&dftid=583&uid=25203&mod=document | Vendor Advisory |