CVE-2025-57685
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3 models, are vulnerable to unauthorized command injection. Attackers can exploit this vulnerability by accessing the /goform/set_serial_cfg interface to gain the highest level of device privileges without authorization, enabling them to remotely execute malicious commands.
Published:Sep 22, 2025
Last Modified:Apr 15, 2026
EPS:Sep 22, 2025
EPSS Score:0.0043
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
B-link
Product
Bl-ac1900
B-link
Bl-ac1900
Vendor
B-link
Product
Bl-ac2100 Az3
B-link
Bl-ac2100 Az3
Vendor
B-link
Product
Bl-wr9000
B-link
Bl-wr9000
Vendor
B-link
Product
Bl-x26
B-link
Bl-x26
Vendor
B-link
Product
Bl-x26 Ac8
B-link
Bl-x26 Ac8
Vendor
B-link
Product
Bl Lte300
B-link
Bl Lte300
Vendor
B-link
Product
Bl Wr4000
B-link
Bl Wr4000
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
