CVE-2025-55423

Published Jan 20, 2026

Last updated 4 months ago

Overview

Description
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Source
cve@mitre.org
NVD status
Analyzed
Products
n104s-r1_firmware, n104v_firmware, n1e_firmware, n1plus_firmware, n1plus-i_firmware, n1v_firmware, n2e_firmware, n2eplus_firmware, n2plus_firmware, n2plus-i_firmware, n2v_firmware, n2vs_firmware, n3_firmware, n3-i_firmware, n5_firmware, n5-i_firmware, n6_firmware, n600_firmware, n6004r_firmware, n602e_firmware, n602eplus_firmware, n602se_firmware, n604_black_firmware, n604a_firmware, n604e_firmware, n604eplus_firmware, n604plus_firmware, n604plus-i_firmware, n604r_firmware, n604rplus_firmware, n604rplus-i_firmware, n604s_firmware, n604se_firmware, n604t_firmware, n604tplus_firmware, n604v_firmware, n604vplus_firmware, n7004ns_firmware, n702bcm_firmware, n702e_firmware, ax11000_firmware, ax2002mesh_firmware, ax2004_firmware, ax2004bcm_firmware, ax2004m_firmware, ax3004bcm_firmware, ax3004itl_firmware, ax8004bcm_firmware, ax8004m_firmware, ax8008m_firmware, a1_firmware, a1004_firmware, a1004ns_firmware, a1004v_firmware, a104_firmware, a104ns_firmware, a104r_firmware, a2003mu_firmware, a2003ns-mu_firmware, a2004_firmware, a2004mu_firmware, a2004ns_firmware, a2004ns-mu_firmware, a2004ns-r_firmware, a2004nsplus_firmware, a2004plus_firmware, a2004r_firmware, a2004se_firmware, a2008_firmware, a3_firmware, a3002mesh_firmware, a3003ns_firmware, a3004_firmware, a3004-dual_firmware, a3004m_firmware, a3004ns_firmware, a3004ns-bcm_firmware, a3004ns-dual_firmware, a3004ns-m_firmware, a3004t_firmware, a3004tw_firmware, a3008-mu_firmware, a304_firmware, a5004ns_firmware, a5004ns-m_firmware, a6004mx_firmware, a6004ns_firmware, a6004ns-m_firmware, a604_firmware, a604-v3_firmware, a604-v5_firmware, a604g-mu_firmware, a604g-skylife_firmware, a604m_firmware, a604mu_firmware, a604r_firmware, a604se_firmware, a604v_firmware, a6ns-m_firmware, a7004m_firmware, a704ns-bcm_firmware, a7ns_firmware, a8004bcm_firmware, a8004itl_firmware, a8004ns-m_firmware, a8004t_firmware, a8004t-xr_firmware, a804ns-mu_firmware, a8ns-m_firmware, a9004m_firmware, a9004m-x2_firmware, ew302n_firmware, n102e_firmware, n102eplus_firmware, n102i_firmware, n102iplus_firmware, n104_black_firmware, n104e_firmware, n104eplus_firmware, n104k_firmware, n104plus_firmware, n104plus-i_firmware, n104q_firmware, n104q-i_firmware, n104r_firmware, n702eplus_firmware, n702r_firmware, n704-a3_firmware, n704bcm_firmware, n704e_firmware, n704eplus_firmware, n704ns_firmware, n704qca_firmware, n704v3_firmware, n8004r_firmware, n8004v_firmware, n804_firmware, n804a_firmware, n804a3_firmware, n804r_firmware, n804t_firmware, n804t3_firmware, n804v_firmware, n904_firmware, n904ns_firmware, n904plus_firmware, n904v_firmware, smart_firmware, q1_firmware, q304_firmware, q504_firmware, q604_firmware, t16000_firmware, t16000m_firmware, t24000_firmware, t24000m_firmware, t3004_firmware, t3008_firmware, t5004_firmware, t5008_firmware, v304_firmware, v504_firmware, v508_firmware

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score
Not currently trending

Configurations