LB-LINK records
18 published records for vendor lb-link.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-256 Plaintext Storage of a Password1
- CWE-259 Use of Hard-coded Password1
- CWE-287 Improper Authentication1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2023-26801No exploit | LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a comlb-link · bl-lte300 firmware · CWE-77 | Critical9.8 | — | 69.7% | Mar 26, 2023 |
39Monitor | CVE-2025-29062No exploit | An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_lb-link · bl-ac2100 firmware · CWE-77 | Critical9.8 | — | 1.1% | Apr 2, 2025 |
39Monitor | CVE-2025-29063No exploit | An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hilb-link · bl-ac2100 firmware · CWE-77 | Critical9.8 | — | 1.1% | Apr 2, 2025 |
39Monitor | CVE-2024-33375No exploit | LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.lb-link · bl-w1210m firmware · CWE-256 | Critical9.8 | — | 0.6% | Jun 14, 2024 |
39Monitor | CVE-2024-51431No exploit | LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.lb-link · bl-wr1300h firmware · CWE-798 | Critical9.8 | — | 0.6% | Nov 1, 2024 |
35Monitor | CVE-2025-57278No exploit | The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handlinlb-link · bl-cpe300m firmware · CWE-287 | High8.8 | — | 0.4% | Sep 9, 2025 |
32Monitor | CVE-2024-33377No exploit | LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page.lb-link · bl-w1210m firmware · CWE-1021 | High8.1 | — | 0.4% | Jun 14, 2024 |
30Monitor | CVE-2025-10773No exploit | B-Link BL-AC2100 Web Management set_delshrpath_cfg delshrpath stack-based overflowlb-link · bl-ac2100 firmware · CWE-119 | High7.4 | — | 4.0% | Sep 21, 2025 |
29Monitor | CVE-2026-4226No exploit | LB-LINK BL-WR9000 get_virtual_cfg sub_44E8D0 stack-based overflowlb-link · bl-wr9000 firmware · CWE-119 | High7.4 | — | 1.1% | Mar 16, 2026 |
29Monitor | CVE-2026-4227No exploit | LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflowlb-link · bl-wr9000 firmware · CWE-119 | High7.4 | — | 1.1% | Mar 16, 2026 |
28Monitor | CVE-2025-7564No exploit | LB-LINK BL-AC3600 shadow hard-coded credentialslb-link · bl-ac3600 firmware · CWE-259 | High7.1 | — | 0.2% | Jul 13, 2025 |
25Monitor | CVE-2025-1610No exploit | LB-LINK AC1900 Router set_blacklist websGetVar os command injectionlb-link · ac1900 firmware · CWE-77 | Medium5.3 | — | 13.2% | Feb 23, 2025 |
25Monitor | CVE-2024-33373No exploit | An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords forlb-link · bl-w1210m firmware · CWE-639 | Medium6.3 | — | 0.3% | Jun 14, 2024 |
24Monitor | CVE-2025-1609No exploit | LB-LINK AC1900 Router set_cmd websGetVar os command injectionlb-link · ac1900 firmware · CWE-77 | Medium5.3 | — | 10.2% | Feb 23, 2025 |
24Monitor | CVE-2025-1608No exploit | LB-LINK AC1900 Router set_manpwd websGetVar os command injectionlb-link · ac1900 firmware · CWE-77 | Medium5.3 | — | 10.2% | Feb 23, 2025 |
22Monitor | CVE-2025-7565No exploit | LB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosurelb-link · bl-ac3600 firmware · CWE-200 | Medium5.5 | — | 0.6% | Jul 14, 2025 |
11Monitor | CVE-2026-4228No exploit | LB-LINK BL-WR9000 set_wifi sub_458754 command injectionlb-link · bl-wr9000 firmware · CWE-74 | Low2.1 | — | 8.9% | Mar 16, 2026 |
10Monitor | CVE-2025-9580No exploit | LB-LINK BL-X26 HTTP set_blacklist os command injectionlb-link · bl-x26 firmware · CWE-77 | Low2.1 | — | 6.7% | Aug 28, 2025 |
- CVE-2023-2680160This week
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a com
CriticalCVSS 9.8No exploitEPSS 70%lb-link · bl-lte300 firmwareMar 26, 2023
- CVE-2025-2906239Monitor
An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_
CriticalCVSS 9.8No exploitEPSS 1%lb-link · bl-ac2100 firmwareApr 2, 2025
- CVE-2025-2906339Monitor
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hi
CriticalCVSS 9.8No exploitEPSS 1%lb-link · bl-ac2100 firmwareApr 2, 2025
- CVE-2024-3337539Monitor
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
CriticalCVSS 9.8No exploitEPSS 1%lb-link · bl-w1210m firmwareJun 14, 2024
- CVE-2024-5143139Monitor
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
CriticalCVSS 9.8No exploitEPSS 1%lb-link · bl-wr1300h firmwareNov 1, 2024
- CVE-2025-5727835Monitor
The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handlin
HighCVSS 8.8No exploitEPSS 0%lb-link · bl-cpe300m firmwareSep 9, 2025
- CVE-2024-3337732Monitor
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page.
HighCVSS 8.1No exploitEPSS 0%lb-link · bl-w1210m firmwareJun 14, 2024
- CVE-2025-1077330Monitor
B-Link BL-AC2100 Web Management set_delshrpath_cfg delshrpath stack-based overflow
HighCVSS 7.4No exploitEPSS 4%lb-link · bl-ac2100 firmwareSep 21, 2025
- CVE-2026-422629Monitor
LB-LINK BL-WR9000 get_virtual_cfg sub_44E8D0 stack-based overflow
HighCVSS 7.4No exploitEPSS 1%lb-link · bl-wr9000 firmwareMar 16, 2026
- CVE-2026-422729Monitor
LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
HighCVSS 7.4No exploitEPSS 1%lb-link · bl-wr9000 firmwareMar 16, 2026
- CVE-2025-756428Monitor
LB-LINK BL-AC3600 shadow hard-coded credentials
HighCVSS 7.1No exploitEPSS 0%lb-link · bl-ac3600 firmwareJul 13, 2025
- CVE-2025-161025Monitor
LB-LINK AC1900 Router set_blacklist websGetVar os command injection
MediumCVSS 5.3No exploitEPSS 13%lb-link · ac1900 firmwareFeb 23, 2025
- CVE-2024-3337325Monitor
An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for
MediumCVSS 6.3No exploitEPSS 0%lb-link · bl-w1210m firmwareJun 14, 2024
- CVE-2025-160924Monitor
LB-LINK AC1900 Router set_cmd websGetVar os command injection
MediumCVSS 5.3No exploitEPSS 10%lb-link · ac1900 firmwareFeb 23, 2025
- CVE-2025-160824Monitor
LB-LINK AC1900 Router set_manpwd websGetVar os command injection
MediumCVSS 5.3No exploitEPSS 10%lb-link · ac1900 firmwareFeb 23, 2025
- CVE-2025-756522Monitor
LB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosure
MediumCVSS 5.5No exploitEPSS 1%lb-link · bl-ac3600 firmwareJul 14, 2025
- CVE-2026-422811Monitor
LB-LINK BL-WR9000 set_wifi sub_458754 command injection
LowCVSS 2.1No exploitEPSS 9%lb-link · bl-wr9000 firmwareMar 16, 2026
- CVE-2025-958010Monitor
LB-LINK BL-X26 HTTP set_blacklist os command injection
LowCVSS 2.1No exploitEPSS 7%lb-link · bl-x26 firmwareAug 28, 2025