PT-2025-25407 · Blink · Lb-Link Bl-Wr9000+7

Published

2025-04-12

·

Updated

2025-07-10

·

CVE-2025-45987

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blink BL-WR9000 version 2.4.9 Blink BL-AC2100 AZ3 version 1.0.4 Blink BL-X10 AC8 version 1.0.5 Blink BL-LTE300 version 1.2.3 Blink BL-F1200 AT1 version 1.0.0 Blink BL-X26 AC8 version 1.2.8 Blink BLAC450M AE4 version 4.0.0 Blink BL-X26 DA3 version 1.2.7
Description The issue concerns multiple command injection vulnerabilities found in various Blink router models. These vulnerabilities can be exploited through the dns1 and dns2 parameters in the bs SetDNSInfo function.
Recommendations For Blink BL-WR9000 version 2.4.9, update the firmware to a version that fixes the command injection vulnerability. For Blink BL-AC2100 AZ3 version 1.0.4, update the firmware to a version that fixes the command injection vulnerability. For Blink BL-X10 AC8 version 1.0.5, update the firmware to a version that fixes the command injection vulnerability. For Blink BL-LTE300 version 1.2.3, update the firmware to a version that fixes the command injection vulnerability. For Blink BL-F1200 AT1 version 1.0.0, update the firmware to a version that fixes the command injection vulnerability. For Blink BL-X26 AC8 version 1.2.8, update the firmware to a version that fixes the command injection vulnerability. For Blink BLAC450M AE4 version 4.0.0, update the firmware to a version that fixes the command injection vulnerability. For Blink BL-X26 DA3 version 1.2.7, update the firmware to a version that fixes the command injection vulnerability. As a temporary workaround, consider restricting access to the bs SetDNSInfo function to minimize the risk of exploitation. Avoid using the dns1 and dns2 parameters in the affected function until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06883
CVE-2025-45987

Affected Products

Blink Bl-Ac2100 Az3
Blink Bl-F1200 At1
Lb-Link Bl-Lte300
Lb-Link Bl-Wr9000
Blink Bl-X10 Ac8
Blink Bl-X26 Ac8
Blink Bl-X26 Da3
Blink Blac450M Ae4