Lb Link develops a focused portfolio of wireless networking devices and firmware, including routers such as the BL WR9000 and AC1900 models that serve consumer and small-business segments. The vendor's disclosures span these access-point and routing products across their respective firmware implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lb Link over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26801CRITICAL LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac | Mar 26, 2023 | 9.8 | 70 | NO | NO |
CVE-2025-1609CRITICAL A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this vulnerability is the function websGetVar of the file /goform/set_cmd. The | Feb 24, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-1610CRITICAL A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of the file /goform/set_blacklist. The manipu | Feb 24, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-4228CRITICAL A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection. It is pos | Mar 16, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-4226CRITICAL A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /goform/get_virtual_cfg. Executing a manipulation can lead to | Mar 16, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-10773HIGH A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath of the file /goform/set_delshrpath_cfg of the component Web M | Sep 22, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-1608CRITICAL A vulnerability, which was classified as critical, was found in LB-LINK AC1900 Router 1.0.2. Affected is the function websGetVar of the file /goform/set_manpwd. The manipulation of | Feb 24, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-9580HIGH A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulat | Aug 28, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-29063CRITICAL An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly. | Apr 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-29062CRITICAL An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice. | Apr 2, 2025 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lb Link.
Media articles that mention a CVE ID that affects a product developed by Lb Link — matched by CVE ID, not by vendor name.