CVE-2025-45984
CRITICAL EPSS 75.6%
Published Jun 13, 20251y ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Published Jun 13, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
75.6% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-77 Command Injection Injection
Affected Products 18
| Vendor | Product | Version | Range |
|---|---|---|---|
| b-link | bl-wr9000_firmware | 2.4.9 | any |
| b-link | bl-wr9000 | * | any |
| b-link | bl-ac1900_firmware | 1.0.2 | any |
| b-link | bl-ac1900 | * | any |
| b-link | bl-ac2100_az3_firmware | 1.0.4 | any |
| b-link | bl-ac2100_az3 | * | any |
| b-link | bl-x10_ac8_firmware | 1.0.5 | any |
| b-link | bl-x10_ac8 | * | any |
| b-link | bl-lte300_firmware | 1.2.3 | any |
| b-link | bl-lte300 | * | any |
| b-link | bl-f1200_at1_firmware | 1.0.0 | any |
| b-link | bl-f1200_at1 | * | any |
| b-link | bl-x26_ac8_firmware | 1.2.8 | any |
| b-link | bl-x26_ac8 | * | any |
| b-link | blac450m_ae4_firmware | 4.0.0 | any |
| b-link | blac450m_ae4 | * | any |
| b-link | bl-x26_da3_firmware | 1.2.7 | any |
| b-link | bl-x26_da3 | * | any |
References 1
- github.com https://github.com/glkfc/IoT-Vulnerability/blob/main/LB-LINK/LB-LINK_routepwd%20Indicates%20the%20unauthorized%20command%20injection/LB-LINK_routepwd%20command%20injection.md
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.