CVE-2025-4076
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Apr 29, 2025
Updated: May 2, 2025
CWE ID 77
CWE ID 74
Summary
CVE-2025-4076 is a critical vulnerability affecting the Password Handler component in LB-LINK BL-AC3600 versions up to 1.0.22. The issue lies in the easy_uci_set_option_string_0 function of the /cgi-bin/lighttpd.cgi file. An attacker can exploit this vulnerability by manipulating the routepwd argument to perform command injection. The attack can be initiated remotely, and the exploit has been made public, increasing the risk of widespread use. Despite early disclosure to the vendor, there has been no response or patch released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.