CVE-2023-26801

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 26, 2023
Updated: Jan 9, 2025
CWE ID 77

Summary

CVE-2023-26801 affects multiple LB-LINK routers, including BL-AC1900_2.0 v1.0.1, BL-WR9000 v2.4.9, BL-X26 v1.2.5, and BL-LTE300 v1.0.8. A command injection vulnerability has been discovered in these devices, which can be exploited by maliciously crafted inputs to the mac, time1, and time2 parameters in the /goform/set_LimitClient_cfg path. An attacker can execute arbitrary commands with administrative privileges, potentially leading to unauthorized access, data theft, or denial-of-service attacks. Users are advised to update their routers to the latest firmware versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share