VYPR

T3008 Firmware

by Iptime

CVEs (1)

  • CVE-2025-55423CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command…