CVE-2025-45984

Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:b-link:bl-wr9000_firmware:2.4.9:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-wr9000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:b-link:bl-ac1900_firmware:1.0.2:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-ac1900:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:b-link:bl-ac2100_az3_firmware:1.0.4:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-ac2100_az3:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:b-link:bl-x10_ac8_firmware:1.0.5:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x10_ac8:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:b-link:bl-lte300_firmware:1.2.3:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-lte300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:b-link:bl-f1200_at1_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-f1200_at1:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:b-link:bl-x26_ac8_firmware:1.2.8:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x26_ac8:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:b-link:blac450m_ae4_firmware:4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:b-link:blac450m_ae4:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:b-link:bl-x26_da3_firmware:1.2.7:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x26_da3:-:*:*:*:*:*:*:*

History

10 Jul 2025, 12:15

Type Values Removed Values Added
CPE cpe:2.3:h:b-link:bl-x26_ac8:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-f1200_at1:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x26_da3:-:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-ac2100_az3_firmware:1.0.4:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x10_ac8:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-ac2100_az3:-:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-x10_ac8_firmware:1.0.5:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-lte300_firmware:1.2.3:*:*:*:*:*:*:*
cpe:2.3:o:b-link:blac450m_ae4_firmware:4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-ac1900_firmware:1.0.2:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-x26_ac8_firmware:1.2.8:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-x26_da3_firmware:1.2.7:*:*:*:*:*:*:*
cpe:2.3:h:b-link:blac450m_ae4:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-lte300:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-wr9000:-:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-f1200_at1_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-wr9000_firmware:2.4.9:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-ac1900:-:*:*:*:*:*:*:*
First Time B-link blac450m Ae4 Firmware
B-link
B-link bl-lte300 Firmware
B-link bl-x10 Ac8 Firmware
B-link bl-ac2100 Az3 Firmware
B-link bl-x26 Da3
B-link bl-ac1900
B-link bl-wr9000 Firmware
B-link blac450m Ae4
B-link bl-x26 Ac8 Firmware
B-link bl-f1200 At1 Firmware
B-link bl-x26 Da3 Firmware
B-link bl-ac2100 Az3
B-link bl-wr9000
B-link bl-lte300
B-link bl-x10 Ac8
B-link bl-x26 Ac8
B-link bl-ac1900 Firmware
B-link bl-f1200 At1
References () https://github.com/glkfc/IoT-Vulnerability/blob/main/LB-LINK/LB-LINK_routepwd%20Indicates%20the%20unauthorized%20command%20injection/LB-LINK_routepwd%20command%20injection.md - () https://github.com/glkfc/IoT-Vulnerability/blob/main/LB-LINK/LB-LINK_routepwd%20Indicates%20the%20unauthorized%20command%20injection/LB-LINK_routepwd%20command%20injection.md - Exploit

13 Jun 2025, 15:15

Type Values Removed Values Added
CWE CWE-77
Summary
  • (es) Se descubrió que los enrutadores Blink BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 y BL-X26_DA3 V1.2.7 contienen una vulnerabilidad de inyección de comandos a través del parámetro routepwd en la función sub_45B238.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

13 Jun 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 12:15

Updated : 2025-07-10 12:15


NVD link : CVE-2025-45984

Mitre link : CVE-2025-45984

CVE.ORG link : CVE-2025-45984


JSON object : View

Products Affected

b-link

  • blac450m_ae4
  • bl-x10_ac8_firmware
  • bl-ac1900
  • bl-ac2100_az3
  • blac450m_ae4_firmware
  • bl-f1200_at1
  • bl-ac2100_az3_firmware
  • bl-wr9000
  • bl-lte300_firmware
  • bl-x26_ac8_firmware
  • bl-x26_da3_firmware
  • bl-x26_da3
  • bl-f1200_at1_firmware
  • bl-x26_ac8
  • bl-ac1900_firmware
  • bl-x10_ac8
  • bl-wr9000_firmware
  • bl-lte300
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')