CVE-2025-55423: Command Injection
A command injection vulnerability exists in the upnprelay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55423?
CVE-2025-55423 has been classified as a critical severity vulnerability due to its potential for OS command injection in multiple ipTIME router models.
How do I fix CVE-2025-55423?
To fix CVE-2025-55423, users should update their affected ipTIME router firmware to the latest version provided by the vendor.
Which ipTIME router models are affected by CVE-2025-55423?
CVE-2025-55423 affects multiple ipTIME router models including A2003NS-MU, N600, A604-V3, A6ns-M, V508, and others within the specified version ranges.
What type of vulnerability is CVE-2025-55423?
CVE-2025-55423 is a command injection vulnerability that allows an attacker to execute arbitrary commands on the system via insufficient input validation.
What are the risks associated with CVE-2025-55423?
The risks associated with CVE-2025-55423 include unauthorized access to router functionalities and potential compromise of the entire network due to OS command execution.