CVE-2025-7574 Details
Description
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web Interface. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A critical vulnerability has been identified in several LB-LINK router models, including the BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P, and BL-WR9000, all versions prior to 20250702. The issue resides in the web management interface, specifically within the 'reboot/restore' function of the '/cgi-bin/lighttpd.cgi' file. This vulnerability stems from improper authentication, allowing remote attackers to execute sensitive operations such as rebooting the device or performing a factory reset. Such actions can disrupt network services and result in the loss of configuration data.
Users are advised to apply restrictive firewalling to mitigate this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2025CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LB-LINK BL-AC1900 | All versions |
CPE
Remediation
| |
| LB-LINK BL-AC2100_AZ3 | All versions |
CPE
Remediation
| |
| LB-LINK BL-AC3600 | All versions |
CPE
Remediation
| |
| LB-LINK BL-AX1800 | All versions |
CPE
Remediation
| |
| LB-LINK BL-AX5400P | All versions |
CPE
Remediation
| |
| LB-LINK BL-WR9000 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | New CVE Received | [email protected] |
Volerion