← Back

Iptime

iptime

13 CVEs • 352 products

Products (352)

Click to collapse
Toggle
C200 Firmware
c200_firmware
Nas3 Firmware
nas3_firmware
Nas4 Firmware
nas4_firmware
Nas Firmware
nas_firmware
N104v Firmware
n104v_firmware
N1e Firmware
n1e_firmware
N1v Firmware
n1v_firmware
N2e Firmware
n2e_firmware
N2v Firmware
n2v_firmware
N2vs Firmware
n2vs_firmware
N3 Firmware
n3_firmware
N3 I Firmware
n3-i_firmware
N5 Firmware
n5_firmware
N5 I Firmware
n5-i_firmware
N6 Firmware
n6_firmware
N600 Firmware
n600_firmware
N602e Firmware
n602e_firmware
N604a Firmware
n604a_firmware
N604e Firmware
n604e_firmware
N604r Firmware
n604r_firmware
N604s Firmware
n604s_firmware
N604t Firmware
n604t_firmware
N604v Firmware
n604v_firmware
N702e Firmware
n702e_firmware
A1 Firmware
a1_firmware
A1004 Firmware
a1004_firmware
A104 Firmware
a104_firmware
A104r Firmware
a104r_firmware
A2004 Firmware
a2004_firmware
A2008 Firmware
a2008_firmware
A3 Firmware
a3_firmware
A3004 Firmware
a3004_firmware
A304 Firmware
a304_firmware

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Iptime
4Ax2004m Firmware
Ax3000q FirmwareAx6000m Firmware+1 more
Jun 17, 2026
Feb 27, 2026
6.0 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows...Show more
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through 15.26.8; ipTIME AX3000Q: through 15.26.8; ipTIME AX6000M: through 15.26.8.Show less
1Iptime
1A8004t Firmware
Jun 17, 2026
Feb 2, 2026
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component VPN Service. Such manipulation leads to...Show more
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component VPN Service. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Iptime
1A8004t Firmware
Jun 17, 2026
Feb 2, 2026
6.6 MEDIUM· v4
6.6 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes b...Show more
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Iptime
1A8004t Firmware
Jun 17, 2026
Feb 2, 2026
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipulation results in imp...Show more
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipulation results in improper authentication. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Iptime
163A1004 Firmware
A1004ns FirmwareA1004v Firmware+160 more
Jun 17, 2026
Jan 20, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() withou...Show more
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.Show less
1Iptime
1Nas Firmware
Jun 17, 2026
Jul 30, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_...Show more
A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking. Since this operation occurs before authentication logic is executed, the vulnerability is exploitable pre-authentication.Show less
1Iptime
3Nas1dual Firmware
Nas2dual FirmwareNas4dual Firmware
Jun 17, 2026
Oct 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker c...Show more
This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.Show less
1Iptime
3Nas1dual Firmware
Nas2dual FirmwareNas4dual Firmware
Jun 17, 2026
Aug 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the roo...Show more
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.Show less
1Iptime
9Nas I Firmware
Nas Ii FirmwareNas Iie Firmware+6 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insu...Show more
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.Show less
1Iptime
1C200 Firmware
Jun 17, 2026
Nov 30, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is tr...Show more
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.Show less
1Iptime
1C200 Firmware
Jun 17, 2026
Nov 22, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.
1Iptime
9Nas I Firmware
Nas Ii FirmwareNas Iie Firmware+6 more
Jun 17, 2026
Feb 23, 2021
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.
1Iptime
1C200 Firmware
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cook...Show more
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value.Show less