CVE-2025-7573: LB-LINK BL-WR9000 lighttpd.cgi bs_GetManPwd information disclosure
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This issue affects the function bsGetManPwd in the library libblinkapi.so of the file /cgi-bin/lighttpd.cgi. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7573?
CVE-2025-7573 is classified as a critical vulnerability.
How do I fix CVE-2025-7573?
To mitigate CVE-2025-7573, update the affected LB-LINK devices to a version beyond 20250702.
Which products are affected by CVE-2025-7573?
CVE-2025-7573 affects LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P, and BL-WR9000 up to version 20250702.
What function is impacted by CVE-2025-7573?
CVE-2025-7573 impacts the function bs_GetManPwd in the library libblinkapi.so.
What type of vulnerabilities does CVE-2025-7573 include?
CVE-2025-7573 includes a critical vulnerability affecting device security through improper handling of sensitive information.