---
id: CVE-2025-9580
title: A security vulnerability has been detected in LB-LINK BL-X26 1.2.8
summary: >-
  A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This
  affects an unknown function of the file /goform/set_blacklist of the component
  HTTP Handler. Such manipulation of the argument mac leads to os command
  injection. Th…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
  - CWE-78
vendor: lb-link
product: bl-x26_firmware
affected:
  - bl-x26_firmware = 1.2.8
published: '2025-08-28'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9580'
references:
  - url: >-
      https://github.com/lin-3-start/lin-cve/blob/main/B-Link%20X26%20V1.2.8-2/B-Link%20X26%20V1.2.8.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/lin-3-start/lin-cve/blob/main/B-Link%20X26%20V1.2.8-2/B-Link%20X26%20V1.2.8.md#3poc
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.321693'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.321693'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.636083'
    label: cna@vuldb.com
  - url: >-
      https://github.com/lin-3-start/lin-cve/blob/main/B-Link%20X26%20V1.2.8-2/B-Link%20X26%20V1.2.8.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/lin-3-start/lin-cve/blob/main/B-Link%20X26%20V1.2.8-2/B-Link%20X26%20V1.2.8.md#3poc
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.06729
epssPercentile: 0.9371
ingestedAt: '2026-09-26T00:22:39.893Z'
---

## Overview

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `bl-x26_firmware = 1.2.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
