CVE-2025-57685 Details
Description
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3 models, are vulnerable to unauthorized command injection. Attackers can exploit this vulnerability by accessing the /goform/set_serial_cfg interface to gain the highest level of device privileges without authorization, enabling them to remotely execute malicious commands.
A command injection vulnerability has been identified in several LB-Link router models, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3. This vulnerability allows attackers to gain unauthorized access to the highest level of device privileges by exploiting the /goform/set_serial_cfg interface. Once exploited, attackers can remotely execute malicious commands on the affected devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2025CISA-ADP
Assessed Nov 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mono7s/LB-Link/blob/main/bs_SetSerial.md | [email protected] | ExploitTechnical Analysis |
| https://www.b-link.net.cn/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| LB-Link BL-AC2100 | All versions |
CPE
Remediation
| |
| LB-Link BL-WR4000 | All versions |
CPE
Remediation
| |
| LB-Link BL-WR9000 | All versions |
CPE
Remediation
| |
| LB-Link BL-AC1900 | All versions |
CPE
Remediation
| |
| LB-Link BL-X26 | All versions |
CPE
Remediation
| |
| LB-Link BL-LTE300 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | CVE Modified | CISA-ADP |
| Oct 28, 2025 | CVE Modified | CISA-ADP |
| Sep 22, 2025 | New CVE Received | [email protected] |
Volerion