OS Command Injection Vulnerability in LB-LINK AC1900 Router
CVE-2025-1610
Key Information:
- Vendor
Lb-link
- Status
- Vendor
- CVE Published:
- 24 February 2025
Badges
What is CVE-2025-1610?
A critical OS command injection vulnerability exists in the LB-LINK AC1900 Router version 1.0.2. This issue arises in the websGetVar function of the /goform/set_blacklist file, where improper handling of the mac/enable argument allows for the execution of arbitrary OS commands. Because this vulnerability can be exploited remotely, it poses a significant threat, and active exploitation attempts have been publicly disclosed. Despite early notifications, the vendor has yet to issue a response regarding this serious flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AC1900 Router 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
