Vulnerability Description
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lb-Link | Bl-Lte300 Firmware | 1.0.8 |
| Lb-Link | Bl-Lte300 | - |
| Lb-Link | Bl-X26 Firmware | 1.2.5 |
| Lb-Link | Bl-X26 | - |
| Lb-Link | Bl-Wr9000 Firmware | 2.4.9 |
| Lb-Link | Bl-Wr9000 | - |
| Lb-Link | Bl-Ac1900 Firmware | 1.0.1 |
| Lb-Link | Bl-Ac1900 | 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/winmt/my-vuls/tree/main/LB-LINK%20BL-AC1900%2C%20BL-WR9000%2CExploitThird Party Advisory
- https://www.akamai.com/blog/security-research/cve-2023-26801-exploited-spreading
- https://github.com/winmt/my-vuls/tree/main/LB-LINK%20BL-AC1900%2C%20BL-WR9000%2CExploitThird Party Advisory
FAQ
What is CVE-2023-26801?
CVE-2023-26801 is a vulnerability with a CVSS score of 9.8 (CRITICAL). LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 p...
How severe is CVE-2023-26801?
CVE-2023-26801 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-26801?
Check the references section above for vendor advisories and patch information. Affected products include: Lb-Link Bl-Lte300 Firmware, Lb-Link Bl-Lte300, Lb-Link Bl-X26 Firmware, Lb-Link Bl-X26, Lb-Link Bl-Wr9000 Firmware.