VendorsipTIMEq304_firmware9.91.2
Vulnerabilities

ipTIME Q304 FIRMWARE 9.91.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-55423
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
Published 2026-01-20 · Analyzed
9.8EPSS 0.038