An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbp | Exploit Third Party Advisory |
| https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7 | Exploit Third Party Advisory |
| https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
29 Apr 2025, 13:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:lb-link:bl-ac2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:lb-link:bl-ac2100:-:*:*:*:*:*:*:* |
|
| First Time |
Lb-link bl-ac2100 Firmware
Lb-link bl-ac2100 Lb-link |
|
| References | () https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7 - Exploit, Third Party Advisory | |
| References | () https://www.yuque.com/jichujiliangdanwei/vwbq9e/grfgkm2kvk6btwbp - Exploit, Third Party Advisory |
02 Apr 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-02 21:15
Updated : 2025-04-29 13:38
NVD link : CVE-2025-29063
Mitre link : CVE-2025-29063
JSON object : View
Products Affected
lb-link
- bl-ac2100
- bl-ac2100_firmware
CWE
No CWE.
