CVE-2026-4228: LB-LINK BL-WR9000 set_wifi sub_458754 command injection
A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub458754 of the file /goform/setwifi. The manipulation results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4228?
CVE-2026-4228 has been categorized as a high-severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-4228?
To mitigate CVE-2026-4228, update the LB-LINK BL-WR9000 firmware to the latest version provided by the vendor that addresses this vulnerability.
What is affected by CVE-2026-4228?
CVE-2026-4228 affects LB-LINK BL-WR9000 devices running version 2.4.9 and below.
Can CVE-2026-4228 be exploited remotely?
Yes, CVE-2026-4228 can be exploited remotely, allowing attackers to execute arbitrary commands.
What is the impact of CVE-2026-4228 on device security?
The impact of CVE-2026-4228 includes unauthorized access and control of the affected LB-LINK BL-WR9000 device.