Lb Link · Lb-Link Ac1900 Router · CVE-2025-1610
**Name of the Vulnerable Software and Affected Versions**
LB-LINK AC1900 Router version 1.0.2
**Description**
The issue concerns an os command injection vulnerability, specifically affecting the `/goform/set blacklist` endpoint, where the `mac` and `enable` variables are involved.
**Recommendations**
For LB-LINK AC1900 Router version 1.0.2, avoid using the `/goform/set blacklist` endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.