CVE Feed

    Dashboard / CVE / CVE-2025-57685

    CVE-2025-57685

    The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3 models, are vulnerable to unauthorized command injection. Attackers can exploit this vulnerability by accessing the /goform/set_serial_cfg interface to gain the highest level of device privileges without authorization, enabling them to remotely execute malicious commands.

    Published:Sep 22, 2025
    Last Modified:Apr 15, 2026
    EPS:Sep 22, 2025
    EPSS Score:0.0043
    CVSS Score:8.8

    Affected Products

    Vendor
    B-link
    Product
    Bl-ac1900
    Vendor
    B-link
    Product
    Bl-ac2100 Az3
    Vendor
    B-link
    Product
    Bl-wr9000
    Vendor
    B-link
    Product
    Bl-x26
    Vendor
    B-link
    Product
    Bl-x26 Ac8
    Vendor
    B-link
    Product
    Bl Lte300
    Vendor
    B-link
    Product
    Bl Wr4000

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High