The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether you use a LB-LINK AC1900 Router / LB-LINK BL-AC1900 (AC1900 Router) and confirm the firmware version is 1.0.2.
If version 1.0.2 is in use, restrict access to the router’s web management interface from the internet (allow only trusted internal IPs, or disable WAN/remote management).
Place the router behind a firewall and block inbound traffic to the router’s management/web ports from the internet.
Deploy network monitoring or protections (IDS/IPS) to detect and prevent suspicious attempts targeting /goform/set_cmd or unusual web requests.
Contact your router vendor or your IT support to obtain the fixed firmware/build for LB-LINK AC1900 Router (AC1900 Router / LB-LINK BL-AC1900); do not rely on the absence of alerts—this issue has a public exploit.
A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this vulnerability is the function websGetVar of the file /goform/set_cmd. The manipulation of the argument cmd leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
In plain language
Written by AI from the record
CVE-2025-1609 is a flaw in certain LB-LINK AC1900 router firmware that lets an attacker remotely run commands on the router; if your small business uses a LB-LINK BL-AC1900/AC1900 Router running version 1.0.2, you should treat this as a real risk and take action.
CVE-2025-1609 is a remote operating system command injection in the LB-LINK AC1900 Router (web handler /goform/set_cmd via websGetVar), where manipulating the `cmd` argument can lead to arbitrary command execution; public exploits exist.
If you're affected
Router takeover
Interception of internet traffic
Device disruption or outages
Possible malware persistence
What is it
This vulnerability is like a backdoor in the router’s web page that’s supposed to run safe commands. With the wrong input, an attacker can trick the router into running their own commands, which can let them take control or disrupt the connection for your business—especially if the router can be reached from the internet.
Who is affected
This matters if your small business uses an LB-LINK AC1900 Router (including LB-LINK BL-AC1900 / AC1900 Router) running version 1.0.2. The attack is remote and needs no user action, and it may only require limited privileges.
If the router is not reachable for management/web access from the internet, the risk is reduced; the main concern is whether an attacker can reach the affected web endpoint from outside your network.
How urgent is it
Treat this as urgent because a public exploit exists and attackers can remotely run operating system commands on the router. Even though it’s rated medium, the practical impact is potentially high because it’s on a network device that controls internet access.
If you’re running firmware 1.0.2 on the affected LB-LINK AC1900 Router, act now to restrict exposure and get updated firmware; don’t wait for signs of compromise.
Check firmware version: confirm whether it is 1.0.2.
Determine reachability: verify whether the router’s web management functions are reachable from the internet. Specifically, check for any WAN/remote management or open inbound access that would allow requests to the affected path /goform/set_cmd.
Validate potential targeting (internal checks)
Review router logs (if available) and any firewall/IDS logs for unusual requests related to /goform/set_cmd, or abnormal patterns consistent with command injection attempts.
If you have packet capture capability, look for POST/GET requests with suspicious cmd parameter usage.
Immediate compensating controls (while awaiting a fixed firmware)
Restrict inbound access: block all inbound WAN traffic to router web/management ports at the perimeter firewall except from a tightly limited set of trusted internal IPs (or disable remote/WAN management entirely).
Add detection/prevention: enable IDS/IPS features or deploy IDS/IPS at the network edge to detect and block requests targeting /goform/set_cmd or command-injection-like payloads.
Upgrade path
Use vendor-provided fixed firmware/build for the affected LB-LINK AC1900 Router. Your primary target is eliminating the vulnerable behavior in the websGetVar handling of /goform/set_cmd and the cmd argument.
If multiple branches exist, upgrade to the earliest version the vendor explicitly states as fixed for CVE-2025-1609.
Workarounds if patching is delayed
Keep the router management interface inaccessible from the internet.
Reduce the attack surface further: if supported, ensure only LAN access is allowed for management, and disable any features that expose web management outside your network.
What to monitor after changes
Continue monitoring IDS/IPS and firewall logs for attempted access to management endpoints.
Monitor for router instability or unexpected connectivity changes (which may indicate attempted or successful exploitation).
Timing note
CISA KEV listing: not listed (so no KEV-driven due date is available from the provided findings). However, public exploit availability means you should not treat this as low-priority.
Technical context
CVE-2025-1609 involves a command injection (CWE-77 / CWE-78) in LB-LINK AC1900 Router’s web handler function websGetVar for /goform/set_cmd. By manipulating the cmd argument, an attacker can trigger execution of arbitrary operating system commands on the router.
Exploitation status: public exploit is available (1 known). CISA KEV: not listed. This suggests the risk is driven by known exploitability rather than purely theoretical exposure.
Attack vector and interaction: remote network access with no user interaction required. Preconditions are stated as LB-LINK AC1900 Router version 1.0.2 in use.
EPSS: provided as a predicted likelihood with a rising trend, but this should not be treated as a mitigation; public exploit availability is the stronger indicator of real-world risk.
Remediation availability in provided findings: a vendor remediation note indicates compensating measures (firewall/IDS-IPS). A specific fixed firmware version was not provided in the findings, so the exact upgrade target must come from the vendor/firmware release notes for this CVE.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.