iptime CVE Vulnerabilities & Metrics

Focus on iptime vulnerabilities and metrics.

Last updated: 21 Aug 2025, 22:25 UTC

About iptime Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with iptime. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total iptime CVEs: 8
Earliest CVE date: 17 Feb 2021, 14:15 UTC
Latest CVE date: 30 Jul 2025, 19:15 UTC

Latest CVE reference: CVE-2025-50464

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical iptime CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.34

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 3
7.0-8.9 1
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS iptime CVEs

These are the five CVEs with the highest CVSS scores for iptime, sorted by severity first and recency.

All CVEs for iptime

CVE-2025-50464 iptime vulnerability CVSS: 0 30 Jul 2025, 19:15 UTC

A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking. Since this operation occurs before authentication logic is executed, the vulnerability is exploitable pre-authentication.

CVE-2022-23771 iptime vulnerability CVSS: 0 17 Oct 2022, 16:15 UTC

This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.

CVE-2022-23765 iptime vulnerability CVSS: 0 17 Aug 2022, 21:15 UTC

This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.

CVE-2021-26620 iptime vulnerability CVSS: 5.0 25 Mar 2022, 19:15 UTC

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

CVE-2020-7879 iptime vulnerability CVSS: 6.8 30 Nov 2021, 19:15 UTC

This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.

CVE-2021-26614 iptime vulnerability CVSS: 10.0 22 Nov 2021, 15:15 UTC

ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.

CVE-2020-7847 iptime vulnerability CVSS: 5.2 23 Feb 2021, 16:15 UTC

The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.

CVE-2020-7848 iptime vulnerability CVSS: 7.7 17 Feb 2021, 14:15 UTC

The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value.