Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-24498 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through 15.26.8; ipTIME AX3000Q: through 15.26.8; ipTIME AX6000M: through 15.26.8. NVD description · AI analysis pending | 6.0 | <1% |
| — | ||
| CVE-2026-1741 | A vulnerability was determined in EFM ipTIME A8004T 14.18.2. A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 6.6 group max | <1% |
| — | ||
| CVE-2025-55423 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2025-50464 | A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking. Since this operation occurs before authentication logic is executed, the vulnerability is exploitable pre-authentication. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2022-23771 | This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-23765 | This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2021-26620 | An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2020-7879 | This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2021-26614 | ius_get.cgi in IpTime C200 camera allows remote code execution. ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-7847 | The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code executio The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36. NVD description · AI analysis pending | 8.0 | <1% |
| — | ||
| CVE-2020-7848 | The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value. NVD description · AI analysis pending | 8.0 | 1% |
| — |