OS Command Injection Vulnerability in LB-LINK AC1900 Router
CVE-2025-1610
Key Information:
- Vendor
- Lb-link
- Status
- Ac1900 Router
- Vendor
- CVE Published:
- 24 February 2025
Badges
Summary
A critical OS command injection vulnerability exists in the LB-LINK AC1900 Router version 1.0.2. This issue arises in the websGetVar function of the /goform/set_blacklist file, where improper handling of the mac/enable argument allows for the execution of arbitrary OS commands. Because this vulnerability can be exploited remotely, it poses a significant threat, and active exploitation attempts have been publicly disclosed. Despite early notifications, the vendor has yet to issue a response regarding this serious flaw.
Affected Version(s)
AC1900 Router 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved