LB-LINK BL-X26
cpe:2.3:h:lb-link:bl-x26:*:*:*:*:*:*:*, +1 more
- v1.2.8
A command injection vulnerability has been identified in the LB-Link BL-X26 router, specifically in version 1.2.8. The issue arises in the HTTP handler, within the file '/goform/set_blacklist'. Manipulating the 'mac' argument allows for OS command injection, which can be executed remotely. This vulnerability requires authentication to exploit.
Exploitation of this vulnerability allows for unauthorized command execution on the affected device.
To reproduce this vulnerability, an authenticated user must send a POST request to '/goform/set_blacklist' with a crafted 'mac' parameter that includes the desired command. The 'enable' parameter must also be set. This can be done using a web browser or a tool like curl, ensuring that the request includes the necessary cookies for authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.