PT-2026-4912 · Pix Link · Pix-Link Lv-Wr21Q

·

CVE-2025-12386

·

Published

2026-01-27

·

Updated

2026-01-31

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pix-Link LV-WR21Q version V108 108 Pix-Link LV-WR21Q (affected versions not specified)
Description The Pix-Link LV-WR21Q device does not require authentication for the /goform/getHomePageInfo API endpoint. This allows a remote, unauthenticated attacker to access the endpoint and potentially retrieve the cleartext password for the access point. The vendor was notified of this issue but did not provide details regarding vulnerable version ranges.
Recommendations Apply a patch or update to a newer version that addresses this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02479
BDU:2026-09000
CVE-2025-12386

Affected Products

Pix-Link Lv-Wr21Q