Vulnerability Description
An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lb-Link | Bl-Ac2100 Firmware | <= 1.0.4 |
| Lb-Link | Bl-Ac2100 | - |
Related Weaknesses (CWE)
References
- https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbpExploitThird Party Advisory
- https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7ExploitThird Party Advisory
- https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbpExploitThird Party Advisory
FAQ
What is CVE-2025-29062?
CVE-2025-29062 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
How severe is CVE-2025-29062?
CVE-2025-29062 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-29062?
Check the references section above for vendor advisories and patch information. Affected products include: Lb-Link Bl-Ac2100 Firmware, Lb-Link Bl-Ac2100.