PT-2026-25638 · Lb Link · Bl-Wr9000

Jfkk

+1

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-4228

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub 458754 of the file /goform/set wifi. The manipulation results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4228

Affected Products

Bl-Wr9000