PT-2025-31550 · Lb Link · Lb-Link Bl-Cpe300M

Ravindu Wickramasinghe

+1

·

Published

2025-05-17

·

Updated

2025-07-31

·

CVE-2025-51569

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions LB-Link BL-CPE300M version 01.01.02P42U14 06
Description A cross-site scripting (XSS) vulnerability exists in the web interface of the router. The /goform/goform get cmd process API endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when a crafted URL is accessed. The issue requires user interaction to exploit.
Recommendations Ensure proper input sanitization is implemented for the cmd parameter in the /goform/goform get cmd process endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-00049
CVE-2025-51569

Affected Products

Lb-Link Bl-Cpe300M