iptime records
13 published records for vendor iptime.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 7.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-287 Improper Authentication2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-284 Improper Access Control1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-749 Exposed Dangerous Method or Function1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-55423Proof of concept | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to iptime · n104s-r1 firmware · CWE-94 | Critical9.8 | — | 3.8% | Jan 20, 2026 |
40Plan | CVE-2021-26614No exploit | IpTime C200 IP camera remote code execution vulnerabilityiptime · c200 firmware · CWE-749 | Critical9.8 | — | 2.5% | Nov 22, 2021 |
39Monitor | CVE-2020-7879No exploit | ipTIME C200 IP Camera command injection vulnerabilityiptime · c200 firmware · CWE-78 | Critical9.8 | — | 1.4% | Nov 30, 2021 |
35Monitor | CVE-2022-23765No exploit | IPTIME NAS family CSRF vulnerabilityiptime · nas1dual firmware · CWE-352 | High8.8 | — | 0.5% | Aug 17, 2022 |
35Monitor | CVE-2022-23771No exploit | IPTIME NAS1DUAL CSRF Vulnerabilityiptime · nas1dual firmware · CWE-352 | High8.8 | — | 0.3% | Oct 17, 2022 |
32Monitor | CVE-2020-7848No exploit | The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script.iptime · c200 firmware · CWE-20 | High8.0 | — | 1.1% | Feb 17, 2021 |
32Monitor | CVE-2020-7847No exploit | The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain iptime · nas-i firmware · CWE-434 | High8.0 | — | 0.5% | Feb 23, 2021 |
30Monitor | CVE-2021-26620No exploit | IPTIME NAS2dual improper authentication vulnerabilityiptime · nas101 firmware · CWE-287 | High7.5 | — | 1.4% | Mar 25, 2022 |
26Monitor | CVE-2026-1741No exploit | EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdooriptime · a8004t firmware · CWE-912 | Medium6.6 | — | 0.7% | Feb 2, 2026 |
26Monitor | CVE-2025-50464No exploit | A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04.iptime · nas firmware · CWE-121 | Medium6.5 | — | 0.5% | Jul 30, 2025 |
24Monitor | CVE-2026-24498No exploit | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc.iptime · t5008 firmware · CWE-200 | Medium6.0 | — | 0.4% | Feb 26, 2026 |
22Monitor | CVE-2026-1740No exploit | EFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authenticationiptime · a8004t firmware · CWE-287 | Medium5.5 | — | 0.5% | Feb 2, 2026 |
8Monitor | CVE-2026-1742No exploit | EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted uploadiptime · a8004t firmware · CWE-284 | Low2.0 | — | 0.4% | Feb 2, 2026 |
- CVE-2025-5542340Plan
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to
CriticalCVSS 9.8Proof of conceptEPSS 4%iptime · n104s-r1 firmwareJan 20, 2026
- CVE-2021-2661440Plan
IpTime C200 IP camera remote code execution vulnerability
CriticalCVSS 9.8No exploitEPSS 3%iptime · c200 firmwareNov 22, 2021
- CVE-2020-787939Monitor
ipTIME C200 IP Camera command injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%iptime · c200 firmwareNov 30, 2021
- CVE-2022-2376535Monitor
IPTIME NAS family CSRF vulnerability
HighCVSS 8.8No exploitEPSS 0%iptime · nas1dual firmwareAug 17, 2022
- CVE-2022-2377135Monitor
IPTIME NAS1DUAL CSRF Vulnerability
HighCVSS 8.8No exploitEPSS 0%iptime · nas1dual firmwareOct 17, 2022
- CVE-2020-784832Monitor
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script.
HighCVSS 8.0No exploitEPSS 1%iptime · c200 firmwareFeb 17, 2021
- CVE-2020-784732Monitor
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain
HighCVSS 8.0No exploitEPSS 1%iptime · nas-i firmwareFeb 23, 2021
- CVE-2021-2662030Monitor
IPTIME NAS2dual improper authentication vulnerability
HighCVSS 7.5No exploitEPSS 1%iptime · nas101 firmwareMar 25, 2022
- CVE-2026-174126Monitor
EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor
MediumCVSS 6.6No exploitEPSS 1%iptime · a8004t firmwareFeb 2, 2026
- CVE-2025-5046426Monitor
A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04.
MediumCVSS 6.5No exploitEPSS 0%iptime · nas firmwareJul 30, 2025
- CVE-2026-2449824Monitor
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc.
MediumCVSS 6.0No exploitEPSS 0%iptime · t5008 firmwareFeb 26, 2026
- CVE-2026-174022Monitor
EFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authentication
MediumCVSS 5.5No exploitEPSS 1%iptime · a8004t firmwareFeb 2, 2026
- CVE-2026-17428Monitor
EFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload
LowCVSS 2.0No exploitEPSS 0%iptime · a8004t firmwareFeb 2, 2026