CVE-2025-1610

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 78
CWE ID 77

Summary

CVE-2025-1610 is a critical vulnerability affecting the LB-LINK AC1900 Router 1.0.2. This issue lies in the websGetVar function of the /goform/set_blacklist file, where the argument mac/enable can be manipulated to execute os commands. The exploitation of this vulnerability can be carried out remotely, and the attack code has been disclosed to the public. Despite early notification, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share