Description
A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
CVSS 4.0 · CNA5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:PCVSS 3.1 · CNA6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:RCVSS 3.0 · CNA6.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:RCVSS 2.0 · CNA6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:URSSVC · CISA-ADP
Exploitationpoc
Automatableno
Technical impactpartial
Affected Products
| Vendor | Product | Affected versions |
|---|---|---|
| LB-LINK | BL-WR9000 | 2.4.9 |
References
4 LinksExploits & PoCs
Third-party advisories
Technical writeups
Detection signatures
Record Details
Published
2026-03-16
Last updated
2026-03-16
Assigner (CNA)
VulDB
Credited to
jfkk (VulDB User); VulDB
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CWE-77 · Command Injection
CWE-74 · Injection
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.