CVE-2025-55423 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding…
Critical CVSS: 9.8

CVE-2025-55423

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Vendor
Iptime
Product
N104s-r1 Firmware
CWE
CWE-94
Yayın Tarihi
2026-01-20 18:16:04
Güncelleme
2026-01-30 20:07:11
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar