CVE-2025-45985: Command Injection
Blink routers BL-WR9000 V2.4.9 , BL-AC2100AZ3 V1.0.4, BL-X10AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200AT1 v1.0.0, BL-X26AC8 v1.2.8, BLAC450MAE4 v4.0.0 and BL-X26DA3 v1.2.7 were discovered to contain a command injection vulnerability via the bsSetSSIDHide function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45985?
The severity of CVE-2025-45985 is critical due to its command injection vulnerability in various Blink router models.
How do I fix CVE-2025-45985?
To fix CVE-2025-45985, update your Blink router firmware to the latest version that addresses this vulnerability.
What Blink router models are affected by CVE-2025-45985?
Affected models by CVE-2025-45985 include Blink BL-WR9000, BL-AC2100_AZ3, BL-X10_AC8, BL-LTE300, BL-F1200_AT1, BL-X26_AC8, BL-AC450M_AE4, and BL-X26_DA3.
What does the command injection vulnerability in CVE-2025-45985 allow an attacker to do?
The command injection vulnerability in CVE-2025-45985 allows attackers to execute arbitrary commands on the affected Blink routers.
Is it safe to use the affected Blink routers with CVE-2025-45985 if they are not updated?
Using affected Blink routers with CVE-2025-45985 without applying the necessary updates poses a significant security risk.