Vulnerability Description
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3 models, are vulnerable to unauthorized command injection. Attackers can exploit this vulnerability by accessing the /goform/set_serial_cfg interface to gain the highest level of device privileges without authorization, enabling them to remotely execute malicious commands.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://bl-ac2100.com
- https://github.com/mono7s/LB-Link/blob/main/bs_SetSerial.md
- https://www.b-link.net.cn/
FAQ
What is CVE-2025-57685?
CVE-2025-57685 is a vulnerability with a CVSS score of 8.8 (HIGH). The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3 models, are vulnerable to unauthorize...
How severe is CVE-2025-57685?
CVE-2025-57685 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57685?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.