CVE-2025-45984 Information

Description

Blink routers BL-WR9000 V2.4.9 BL-AC1900 V1.0.2 BL-AC2100_AZ3 V1.0.4 BL-X10_AC8 V1.0.5 BL-LTE300 V1.2.3 BL-F1200_AT1 V1.0.0 BL-X26_AC8 V1.2.8 BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function.

Reference

https://github.com/glkfc/IoT-Vulnerability/blob/main/LB-LINK/LB-LINK_routepwd%20Indicates%20the%20unauthorized%20command%20injection/LB-LINK_routepwd%20command%20injection.md

CNNVD-202506-1733 (Published: 2025-06-13)

Share on: