CVE-2025-29063: Command Injection
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/sethidessidcfg is not handled properly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29063?
CVE-2025-29063 has a high severity rating as it allows remote code execution, posing significant risk to affected systems.
How do I fix CVE-2025-29063?
To mitigate CVE-2025-29063, upgrade the BL-AC2100 firmware to version V1.0.5 or later, which addresses this vulnerability.
What is the impact of CVE-2025-29063?
CVE-2025-29063 can allow attackers to execute arbitrary code on the affected device, potentially leading to unauthorized access or control.
Which devices are affected by CVE-2025-29063?
CVE-2025-29063 affects the BL-AC2100 model running firmware version V1.0.4 and earlier.
Is CVE-2025-29063 being actively exploited?
As of the latest reports, there is potential for exploitation of CVE-2025-29063, so immediate action is recommended for users of affected products.