PT-2025-35131 · Lb Link · Lb-Link Bl-X26

Qmssdxn

·

Published

2025-08-16

·

Updated

2025-09-12

·

CVE-2025-9580

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LB-LINK BL-X26 version 1.2.8
Description A security issue has been identified in LB-LINK BL-X26 version 1.2.8 related to the HTTP Handler component. Manipulation of the mac argument in the /goform/set blacklist file can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed.
Recommendations As a temporary workaround, consider restricting access to the /goform/set blacklist file to minimize the risk of exploitation. Avoid using the mac parameter in the affected /goform/set blacklist API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00342
CVE-2025-9580

Affected Products

Lb-Link Bl-X26