CVE-2025-29063
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 77
Summary
CVE-2025-29063 is a vulnerability affecting BL-AC2100 V1.0.4 and older versions. An attacker can exploit this issue by sending malicious data through the enable parameter in the /goform/set_hidessid_cfg request. The vulnerable component fails to handle this input appropriately, resulting in the execution of arbitrary code. This vulnerability poses a significant risk as it allows remote attackers to gain unauthorized access to affected devices. Users are strongly encouraged to update their software to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.