Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function.
History

Thu, 10 Jul 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared B-link
B-link bl-ac1900
B-link bl-ac1900 Firmware
B-link bl-ac2100 Az3
B-link bl-ac2100 Az3 Firmware
B-link bl-f1200 At1
B-link bl-f1200 At1 Firmware
B-link bl-lte300
B-link bl-lte300 Firmware
B-link bl-wr9000
B-link bl-wr9000 Firmware
B-link bl-x10 Ac8
B-link bl-x10 Ac8 Firmware
B-link bl-x26 Ac8
B-link bl-x26 Ac8 Firmware
B-link bl-x26 Da3
B-link bl-x26 Da3 Firmware
B-link blac450m Ae4
B-link blac450m Ae4 Firmware
CPEs cpe:2.3:h:b-link:bl-ac1900:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-ac2100_az3:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-f1200_at1:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-lte300:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-wr9000:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x10_ac8:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x26_ac8:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:bl-x26_da3:-:*:*:*:*:*:*:*
cpe:2.3:h:b-link:blac450m_ae4:-:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-ac1900_firmware:1.0.2:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-ac2100_az3_firmware:1.0.4:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-f1200_at1_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-lte300_firmware:1.2.3:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-wr9000_firmware:2.4.9:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-x10_ac8_firmware:1.0.5:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-x26_ac8_firmware:1.2.8:*:*:*:*:*:*:*
cpe:2.3:o:b-link:bl-x26_da3_firmware:1.2.7:*:*:*:*:*:*:*
cpe:2.3:o:b-link:blac450m_ae4_firmware:4.0.0:*:*:*:*:*:*:*
Vendors & Products B-link
B-link bl-ac1900
B-link bl-ac1900 Firmware
B-link bl-ac2100 Az3
B-link bl-ac2100 Az3 Firmware
B-link bl-f1200 At1
B-link bl-f1200 At1 Firmware
B-link bl-lte300
B-link bl-lte300 Firmware
B-link bl-wr9000
B-link bl-wr9000 Firmware
B-link bl-x10 Ac8
B-link bl-x10 Ac8 Firmware
B-link bl-x26 Ac8
B-link bl-x26 Ac8 Firmware
B-link bl-x26 Da3
B-link bl-x26 Da3 Firmware
B-link blac450m Ae4
B-link blac450m Ae4 Firmware

Fri, 13 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 13 Jun 2025 11:45:00 +0000

Type Values Removed Values Added
Description Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-06-13T00:00:00.000Z

Updated: 2025-06-13T14:15:14.650Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45984

cve-icon Vulnrichment

Updated: 2025-06-13T14:13:57.505Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-13T12:15:33.217

Modified: 2025-07-10T12:15:37.927

Link: CVE-2025-45984

cve-icon Redhat

No data.