VendorsipTIMEa8004t_firmwareall versions
Vulnerabilities

ipTIME A8004T

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-55423
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Published 2026-01-20 · Analyzed
9.8EPSS 0.038
CVE-2026-1740
EFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authentication
Published 2026-02-02 · Analyzed
9.8EPSS 0.005
CVE-2026-1742
EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload
Published 2026-02-02 · Analyzed
7.2EPSS 0.004
CVE-2026-1741
EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor
Published 2026-02-02 · Analyzed
6.8EPSS 0.007