PT-2025-31550 · Lb Link · Lb-Link Bl-Cpe300M
Ravindu Wickramasinghe
+1
·
Published
2025-05-17
·
Updated
2025-07-31
·
CVE-2025-51569
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
LB-Link BL-CPE300M version 01.01.02P42U14 06
Description
A cross-site scripting (XSS) vulnerability exists in the web interface of the router. The
/goform/goform get cmd process API endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when a crafted URL is accessed. The issue requires user interaction to exploit.Recommendations
Ensure proper input sanitization is implemented for the
cmd parameter in the /goform/goform get cmd process endpoint.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lb-Link Bl-Cpe300M