CVE-2025-9579: LB-LINK BL-X26 HTTP set_hidessid_cfg os command injection
A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/sethidessidcfg of the component HTTP Handler. This manipulation of the argument enable causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9579?
CVE-2025-9579 has a high severity rating due to the risk of remote command injection.
How do I fix CVE-2025-9579?
To fix CVE-2025-9579, update the firmware of LB-LINK BL-X26 to the latest version provided by the manufacturer.
What components are affected by CVE-2025-9579?
CVE-2025-9579 affects the HTTP Handler component, specifically the /goform/set_hidessid_cfg function.
Can CVE-2025-9579 be exploited remotely?
Yes, CVE-2025-9579 can be exploited remotely, allowing attackers to perform command injection.
What should I do if I am affected by CVE-2025-9579?
If you are affected by CVE-2025-9579, it's recommended to immediately apply the firmware update and change default settings.