CVE-2025-29062

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 77

Summary

CVE-2025-29062 is a vulnerability affecting BL-AC2100 devices with firmware versions below V1.0.4. This issue permits a remote attacker to execute arbitrary code by exploiting an vulnerability in the goahead webservice, specifically in the set_LimitClient_cfg function. The time1 and time2 parameters are the attack vectors in this case. This vulnerability poses a significant risk to the targeted devices, potentially leading to unauthorized access, data theft, or system compromise. It is recommended that users immediately update their devices to the latest firmware version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share