CVE-2025-45987: Command Injection
Blink routers BL-WR9000 V2.4.9 , BL-AC2100AZ3 V1.0.4, BL-X10AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200AT1 v1.0.0, BL-X26AC8 v1.2.8, BLAC450MAE4 v4.0.0 and BL-X26DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bsSetDNSInfo function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45987?
The severity of CVE-2025-45987 is categorized as critical due to its command injection vulnerabilities that allow remote exploitation.
How do I fix CVE-2025-45987?
To fix CVE-2025-45987, apply the latest firmware updates provided by Blink for your affected router models.
Which products are affected by CVE-2025-45987?
CVE-2025-45987 affects several Blink router models including BL-WR9000, BL-AC2100_AZ3, BL-X10_AC8, BL-LTE300, BL-F1200_AT1, BL-X26_AC8, BLAC450M_AE4, and BL-X26_DA3.
What types of vulnerabilities are present in CVE-2025-45987?
CVE-2025-45987 contains multiple command injection vulnerabilities found in the dns1 and dns2 parameters.
Can CVE-2025-45987 potentially allow remote access to my network?
Yes, the command injection vulnerabilities in CVE-2025-45987 can potentially allow an attacker to gain unauthorized remote access to your network.