Skip to content
Noroxi

iptime records

13 published records for vendor iptime.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
7.7%
Median publish → KEV
No record has entered KEV

All records

13 records
  • A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    iptime · n104s-r1 firmwareJan 20, 2026

  • IpTime C200 IP camera remote code execution vulnerability

    CriticalCVSS 9.8No exploitEPSS 3%

    iptime · c200 firmwareNov 22, 2021

  • CVE-2020-7879
    39Monitor

    ipTIME C200 IP Camera command injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    iptime · c200 firmwareNov 30, 2021

  • IPTIME NAS family CSRF vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    iptime · nas1dual firmwareAug 17, 2022

  • IPTIME NAS1DUAL CSRF Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    iptime · nas1dual firmwareOct 17, 2022

  • CVE-2020-7848
    32Monitor

    The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script.

    HighCVSS 8.0No exploitEPSS 1%

    iptime · c200 firmwareFeb 17, 2021

  • CVE-2020-7847
    32Monitor

    The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain

    HighCVSS 8.0No exploitEPSS 1%

    iptime · nas-i firmwareFeb 23, 2021

  • IPTIME NAS2dual improper authentication vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    iptime · nas101 firmwareMar 25, 2022

  • CVE-2026-1741
    26Monitor

    EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor

    MediumCVSS 6.6No exploitEPSS 1%

    iptime · a8004t firmwareFeb 2, 2026

  • A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04.

    MediumCVSS 6.5No exploitEPSS 0%

    iptime · nas firmwareJul 30, 2025

  • Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc.

    MediumCVSS 6.0No exploitEPSS 0%

    iptime · t5008 firmwareFeb 26, 2026

  • CVE-2026-1740
    22Monitor

    EFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authentication

    MediumCVSS 5.5No exploitEPSS 1%

    iptime · a8004t firmwareFeb 2, 2026

  • EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload

    LowCVSS 2.0No exploitEPSS 0%

    iptime · a8004t firmwareFeb 2, 2026