CVE-2025-45986: Command Injection
Blink routers BL-WR9000 V2.4.9 , BL-AC2100AZ3 V1.0.4, BL-X10AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200AT1 v1.0.0, BL-X26AC8 v1.2.8, BLAC450MAE4 v4.0.0 and BL-X26DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac parameter in the bsSetMacBlack function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45986?
CVE-2025-45986 is considered a critical command injection vulnerability that can allow attackers to execute arbitrary commands on the affected Blink routers.
How do I fix CVE-2025-45986?
To mitigate CVE-2025-45986, update the firmware of affected Blink routers to the latest version provided by the manufacturer.
Which devices are affected by CVE-2025-45986?
CVE-2025-45986 impacts multiple models of Blink routers including BL-WR9000, BL-AC2100_AZ3, BL-X10_AC8, and others listed in the advisory.
What is the impact of CVE-2025-45986 on affected devices?
Exploitation of CVE-2025-45986 can lead to unauthorized command execution, potentially compromising device integrity and security.
Is CVE-2025-45986 being actively exploited?
There have been reports indicating that CVE-2025-45986 is actively exploited in the wild, emphasizing the urgency for immediate updates.