Buffer Overflow Vulnerability in LB-LINK BL-WR9000 Router
CVE-2026-4227
Key Information:
Badges
What is CVE-2026-4227?
A security flaw exists in the LB-LINK BL-WR9000 router, specifically within the sub_44D844 function located in /goform/get_hidessid_cfg. This vulnerability allows for a remote attacker to manipulate the function, leading to a buffer overflow. Such an exploit presents significant risks, as it may allow unauthorized access or control over the router. Despite early notification of the issue, the vendor has not responded to the disclosure, leaving users at potential risk of exploitation.
Affected Version(s)
BL-WR9000 2.4.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
