Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Iptime

First CVE: Feb 17, 2021Active for: 5 yearsTotal CVEs: 13
34.1
VTI Score
Medium

Iptime develops a portfolio of network-attached storage appliances and wireless routers targeted at small-to-medium enterprise and consumer markets, with vulnerabilities clustering across firmware and administrative interfaces. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through web-facing weakness classes including cross-site request forgery, improper authentication, unrestricted file uploads, and exposed dangerous methods, reflecting the accessibility and configuration exposure endemic to remotely managed network devices. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Iptime over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2021
5 years ago
Most Recent CVE
Feb 27, 2026
148 days ago

Products(352 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-55423CRITICAL
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an u
Jan 20, 20269.832NONO
CVE-2026-1740CRITICAL
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup In
Feb 2, 20269.831NONO
CVE-2020-7879CRITICAL
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans
Nov 30, 20219.830NONO
CVE-2021-26614CRITICAL
ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the ar
Nov 22, 20219.830NONO
CVE-2022-23771HIGH
This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST req
Oct 17, 20228.828NONO
CVE-2021-26620HIGH
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by
Mar 25, 20227.525NONO
CVE-2026-1742HIGH
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component
Feb 2, 20267.224NONO
CVE-2026-1741MEDIUM
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This m
Feb 2, 20266.623NONO
CVE-2020-7847HIGH
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affect
Feb 23, 20218.023NONO
CVE-2026-24498HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, E
Feb 27, 20267.522NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
15%
54%
31%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (15.4%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low2 (15.4%)
High2 (15.4%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Iptime.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Iptime — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Iptime's Products

View all 3 CNAs →

Top CWEs