CVE-2025-9580Medium· 6.3▾ SunlitA security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. Th…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 1.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
6.7%
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
bl-x26_firmware = 1.2.8Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-9579Medium· 6.3A weakness has been identified in LB-LINK BL-X26 1.2.8
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2026-35867Low· 3.1A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able …
CVE-2025-10619Medium· 6.3A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13
CVE-2025-30264High· 8.8A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0