CVE-2025-51569: XSS
A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U1406 router's web interface. The /goform/goformgetcmdprocess endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when the crafted URL is accessed. The issue requires user interaction to exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51569?
CVE-2025-51569 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-51569?
To fix CVE-2025-51569, ensure that the router's firmware is updated to the latest version provided by LB-Link.
What does CVE-2025-51569 affect?
CVE-2025-51569 affects the LB-Link BL-CPE300M router, specifically its web interface.
What kind of attack can be executed through CVE-2025-51569?
CVE-2025-51569 allows unauthenticated attackers to execute cross-site scripting (XSS) attacks through user input.
Is user authentication necessary to exploit CVE-2025-51569?
No, CVE-2025-51569 can be exploited by unauthenticated attackers, making it particularly concerning.