PT-2025-29424 · Lb Link · Blink Bl-Ac2100 Az3+5
Waiwai24
·
Published
2025-07-02
·
Updated
2025-07-19
·
CVE-2025-7574
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LB-LINK BL-AC1900, BL-AC2100 AZ3, BL-AC3600, BL-AX1800, BL-AX5400P, BL-WR9000 versions up to 20250702
Description
A critical vulnerability exists in the Web Interface component of the affected devices. The vulnerability is related to the
reboot/restore function within the /cgi-bin/lighttpd.cgi file, leading to improper authentication. This allows for remote attacks. The exploit for this issue has been publicly disclosed. The vendor was informed of the vulnerability but did not respond.Recommendations
LB-LINK BL-AC1900 versions prior to 20250702
LB-LINK BL-AC2100 AZ3 versions prior to 20250702
LB-LINK BL-AC3600 versions prior to 20250702
LB-LINK BL-AX1800 versions prior to 20250702
LB-LINK BL-AX5400P versions prior to 20250702
LB-LINK BL-WR9000 versions prior to 20250702
As a temporary workaround, consider disabling access to the
/cgi-bin/lighttpd.cgi file until a patch is available.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lb-Link Bl-Ac1900
Blink Bl-Ac2100 Az3
Lb-Link Bl-Ac3600
Lb-Link Bl-Ax1800
Lb-Link Bl-Ax5400P
Lb-Link Bl-Wr9000