CVE-2025-55423

CRITICALCVSS 9.8/10EPSS 3.33%

Last modified

CVE-2025-55423 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.. EPSS estimates a 3.33% chance of exploitation in the next 30 days.

Description

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
3.33%

87.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IptimeN104s-R1 Firmware>= 9.90.8, <= 10.02.2
IptimeN104v Firmware>= 9.90.8, <= 10.06.8
IptimeN1e Firmware>= 9.90.8, <= 10.06.8
IptimeN1plus Firmware>= 9.90.8, <= 10.06.8
IptimeN1plus-I Firmware>= 9.99.6, <= 10.06.8
IptimeN1v Firmware>= 11.01.2, <= 12.07.6
IptimeN2e Firmware>= 9.90.8, <= 10.06.8
IptimeN2eplus Firmware>= 9.90.8, <= 10.06.8
IptimeN2plus Firmware>= 9.90.8, <= 10.06.8
IptimeN2plus-I Firmware>= 9.99.6, <= 10.06.8
IptimeN2v Firmware>= 10.09.2, <= 12.16.8
IptimeN2vs Firmware12.16.8
IptimeN3 Firmware>= 9.93.2, <= 10.06.8
IptimeN3-I Firmware>= 9.99.6, <= 10.06.8
IptimeN5 Firmware>= 9.90.8, <= 10.06.8
IptimeN5-I Firmware>= 9.99.6, <= 10.06.8
IptimeN6 Firmware>= 9.96.8, <= 10.06.8
IptimeN600 Firmware>= 10.00.8, <= 12.16.2
IptimeN6004r Firmware>= 9.90.8, <= 10.02.2
IptimeN602e Firmware>= 11.96.6, <= 12.16.8
IptimeN602eplus Firmware>= 12.14.2, <= 12.16.2
IptimeN602se Firmware>= 14.19.0, <= 14.19.4
IptimeN604 Black Firmware>= 9.93.8, <= 12.16.2
IptimeN604a Firmware>= 9.90.8, <= 10.06.8
IptimeN604e Firmware>= 10.09.2, <= 14.19.4
IptimeN604eplus Firmware>= 12.14.2, <= 14.19.4
IptimeN604plus Firmware>= 9.90.8, <= 12.15.2
IptimeN604plus-I Firmware>= 9.99.6, <= 12.14.6
IptimeN604r Firmware>= 9.90.8, <= 10.06.8
IptimeN604rplus Firmware>= 9.90.8, <= 10.06.8
IptimeN604rplus-I Firmware>= 9.99.6, <= 10.06.8
IptimeN604s Firmware>= 9.90.8, <= 10.06.8
IptimeN604se Firmware>= 14.18.4, <= 14.19.4
IptimeN604t Firmware>= 9.90.8, <= 10.03.2
IptimeN604tplus Firmware>= 9.90.8, <= 10.03.2
IptimeN604v Firmware>= 9.90.8, <= 10.06.8
IptimeN604vplus Firmware>= 9.90.8, <= 10.06.8
IptimeN7004ns Firmware9.91.2
IptimeN702bcm Firmware>= 9.90.8, <= 12.16.2
IptimeN702e Firmware>= 10.09.2, <= 12.16.2
IptimeAx11000 Firmware>= 14.16.6, <= 14.19.4
IptimeAx2002mesh Firmware>= 14.16.6, <= 14.19.4
IptimeAx2004 Firmware>= 14.17.4, <= 14.19.4
IptimeAx2004bcm Firmware>= 12.04.2, <= 14.19.4
IptimeAx2004m Firmware>= 14.02.0, <= 14.19.4
IptimeAx3004bcm Firmware>= 14.16.2, <= 14.19.4
IptimeAx3004itl Firmware>= 12.01.2, <= 14.19.4
IptimeAx8004bcm Firmware>= 11.97.2, <= 14.19.4
IptimeAx8004m Firmware>= 14.05.2, <= 14.19.4
IptimeAx8008m Firmware>= 14.15.4, <= 14.19.4

Showing 50 of 164 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-55423?
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
How severe is CVE-2025-55423?
CVE-2025-55423 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 3.33% probability of exploitation in the next 30 days.
How do I fix CVE-2025-55423?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-55423?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST