github.com
https://github.com/winmt/my-vuls/tree/main/LB-LINK%20BL-AC1900%2C%20BL-WR9000%2C%20BL-X26%20and%20BL-LTE300%20Wireless%20Routers CVE-2023-26801
CRITICAL
lb-link bl-lte300_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2023-26801 has a selected CVSS score of 9.8 (critical).
Description
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 1, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
bl-lte300_firmwareBrowse lb-link / bl-lte300_firmware | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-26801 akamai.com
https://www.akamai.com/blog/security-research/cve-2023-26801-exploited-spreading-mirai-botnet