Iptime develops a portfolio of network-attached storage appliances and wireless routers targeted at small-to-medium enterprise and consumer markets, with vulnerabilities clustering across firmware and administrative interfaces. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through web-facing weakness classes including cross-site request forgery, improper authentication, unrestricted file uploads, and exposed dangerous methods, reflecting the accessibility and configuration exposure endemic to remotely managed network devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iptime over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55423CRITICAL A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an u | Jan 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-1740CRITICAL A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup In | Feb 2, 2026 | 9.8 | 31 | NO | NO |
CVE-2020-7879CRITICAL This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans | Nov 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-26614CRITICAL ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the ar | Nov 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-23771HIGH This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST req | Oct 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-26620HIGH An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by | Mar 25, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-1742HIGH A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component | Feb 2, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-1741MEDIUM A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This m | Feb 2, 2026 | 6.6 | 23 | NO | NO |
CVE-2020-7847HIGH The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affect | Feb 23, 2021 | 8.0 | 23 | NO | NO |
CVE-2026-24498HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, E | Feb 27, 2026 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iptime.
Media articles that mention a CVE ID that affects a product developed by Iptime — matched by CVE ID, not by vendor name.