LB-LINK BL-X26
cpe:2.3:h:lb-link:bl-x26:*:*:*:*:*:*:*, +1 more
- v1.2.8
A command injection vulnerability has been identified in the LB-LINK BL-X26 router, specifically in version 1.2.8. The issue arises within an unknown function of the file '/goform/set_hidessid_cfg', part of the HTTP handler component. This vulnerability allows for remote exploitation by manipulating the 'enable' argument, leading to unauthorized command execution on the device.
Exploitation of this vulnerability allows for unauthorized command execution on the affected router.
To reproduce this vulnerability, send a POST request to '/goform/set_hidessid_cfg' with the 'type' parameter set to 'sethide2' and the 'enable' parameter containing the command to be executed, such as 'ls>/etc_ro/web/3.txt'. Include a valid 'user' cookie with the value 'admin' to authenticate the request.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.