CVE-2025-55423
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
CRITICAL · CVSS 9.8
EPSS 0.00665
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0