CVE-2025-29062: Command Injection
Published Apr 2, 2025
·Updated
An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the setLimitClientcfg of the goahead webservice.
Affected Software
3 affected components
BL AC2100<=1.0.4
All of the following
LB-LINK Bl-ac2100 Firmware<=1.0.4
LB-LINK Bl-ac2100
Event History
Apr 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29062?
CVE-2025-29062 is considered a critical vulnerability due to its potential for remote arbitrary code execution.
2
How do I fix CVE-2025-29062?
To fix CVE-2025-29062, update the BL-AC2100 firmware to a version later than 1.0.4.
3
Which products are affected by CVE-2025-29062?
CVE-2025-29062 affects the BL-AC2100 devices running version 1.0.4 or earlier.
4
What are the implications of exploiting CVE-2025-29062?
Exploiting CVE-2025-29062 allows an attacker to execute arbitrary code on the affected device, potentially compromising its security and functionality.
5
How can I determine if my device is vulnerable to CVE-2025-29062?
You can determine if your device is vulnerable to CVE-2025-29062 by checking if it is a BL-AC2100 running version 1.0.4 or earlier.