ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-4226
+2 in the same advisory: …4227 …4228
A weakness has been identified in LB-LINK BL-WR9000 2.4.9.

A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /goform/get_virtual_cfg. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.4
group max
<1% PoC
  • lb-link bl-wr9000 firmware
CVE-2025-10773
A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3.

A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath of the file /goform/set_delshrpath_cfg of the component Web Management Interface. The manipulation of the argument Type results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.44% PoC
  • lb-link bl-ac2100 firmware
CVE-2025-57278
The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling.

The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or verifying client identity. There are no session tokens, cookies, or unique identifiers in place. This flaw allows an attacker to obtain full administrative access simply by configuring their device to use the same IP address as a previously authenticated user. This results in a complete authentication bypass.

NVD description · AI analysis pending
8.8<1% PoC
  • lb-link bl-cpe300m firmware
CVE-2025-9580
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8.

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.17% PoC ×2
  • lb-link bl-x26 firmware
CVE-2025-7564
+1 in the same advisory: …7565
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22.

A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.1
group max
<1% PoC ×2
  • lb-link bl-ac3600 firmware
CVE-2025-29063
+1 in the same advisory: …29062
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not ha

An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.

NVD description · AI analysis pending
9.81% PoC ×2
  • lb-link bl-ac2100 firmware
CVE-2025-1610
+2 in the same advisory: …1609 …1608
A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical.

A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of the file /goform/set_blacklist. The manipulation of the argument mac/enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.313% PoC
  • lb-link ac1900 firmware
CVE-2024-51431
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

NVD description · AI analysis pending
9.8<1% PoC
  • lb-link bl-wr1300h firmware
CVE-2024-33375
+2 in the same advisory: …33377 …33373
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • lb-link bl-w1210m firmware
CVE-2023-26801
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulne

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.

NVD description · AI analysis pending
9.870% PoC
  • lb-link bl-lte300 firmware
  • lb-link bl-x26 firmware
  • lb-link bl-wr9000 firmware
  • +1 more