CVE-2025-7574 is a critical improper authentication vulnerability affecting multiple LB-LINK router models, including the BL-AC1900 and BL-AC2100_AZ3, up to firmware version 20250702. This flaw in the web interface's /cgi-bin/lighttpd.cgi component allows unauthenticated remote attackers to trigger device reboots or factory resets. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity, leading to complete loss of confidentiality, integrity, and availability. Public exploit details are available, and while not yet in CISA's KEV catalog, it has garnered community discussion, with no vendor response or patch available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| LB-LINK | BL-AC1900 | 20250702CNA affected | |
| LB-LINK | BL-AC2100 AZ3 | 20250702CNA affected | |
| LB-LINK | BL-AC3600 | 20250702CNA affected | |
| LB-LINK | BL-AX1800 | 20250702CNA affected | |
| LB-LINK | BL-AX5400P | 20250702CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.