CVE-2025-45987 Details
Description
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.
Multiple command injection vulnerabilities have been identified in various Blink router models, including the BL-WR9000, BL-AC2100_AZ3, BL-X10_AC8, BL-LTE300, BL-F1200_AT1, BL-X26_AC8, BL-AC450M_AE4, and BL-X26_DA3. These vulnerabilities arise in the 'bs_SetDNSInfo' function, where the 'dns1' and 'dns2' parameters can be exploited to inject unauthorized commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| b-link bl-wr9000 firmware | 2.4.9 |
CPE
Remediation
| |
| b-link bl-wr9000 | All versions |
CPE
Remediation
| |
| b-link bl-ac2100 az3 firmware | 1.0.4 |
CPE
Remediation
| |
| b-link bl-ac2100 az3 | All versions |
CPE
Remediation
| |
| b-link bl-lte300 firmware | 1.2.3 |
CPE
Remediation
| |
| b-link bl-lte300 | All versions |
CPE
Remediation
| |
| b-link bl-f1200 at1 firmware | 1.0.0 |
CPE
Remediation
| |
| b-link bl-f1200 at1 | All versions |
CPE
Remediation
| |
| b-link bl-x26 ac8 firmware | 1.2.8 |
CPE
Remediation
| |
| b-link bl-x26 ac8 | All versions |
CPE
Remediation
| |
| b-link blac450m ae4 firmware | 4.0.0 |
CPE
Remediation
| |
| b-link blac450m ae4 | All versions |
CPE
Remediation
| |
| b-link bl-x26 da3 firmware | 1.2.7 |
CPE
Remediation
| |
| b-link bl-x26 da3 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | Initial Analysis | [email protected] |
| Jun 13, 2025 | CVE Modified | CISA-ADP |
| Jun 13, 2025 | New CVE Received | [email protected] |