Lb-link
5 CVEs tracked since 2025. Since Jul 2025, none of them reached CISA KEV.
Lb-link CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-07 | 5 | 0 |
Products
The products that kept showing up in Lb-link's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Lb-link.
- CVE-2026-96606LB-Link BL-CPE600EU Configuration Backup Mifi_config.bin information disclosure5.3
- CVE-2026-35867A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deploy...3.1
- CVE-2026-19971LB-Link WR1210M Backup Endpoint backup.cgi main missing authentication4.7
- CVE-2026-19901LB-LINK X-PRO easycwmp hard-coded credentials8.1
- CVE-2026-19900LB-LINK X-PRO shadow hard-coded credentials8.1
- CVE-2026-4228LB-LINK BL-WR9000 set_wifi sub_458754 command injection6.3
- CVE-2026-4227LB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow8.8
- CVE-2026-4226LB-LINK BL-WR9000 get_virtual_cfg sub_44E8D0 stack-based overflow8.8
- CVE-2025-10773B-Link BL-AC2100 Web Management set_delshrpath_cfg delshrpath stack-based overflow8.8
- CVE-2025-57278The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address,...8.8
- CVE-2025-9580LB-LINK BL-X26 HTTP set_blacklist os command injection6.3
- CVE-2025-9579LB-LINK BL-X26 HTTP set_hidessid_cfg os command injection6.3
- CVE-2025-7574LB-LINK BL-WR9000 Web Interface lighttpd.cgi restore improper authentication9.8
- CVE-2025-7573LB-LINK BL-WR9000 lighttpd.cgi bs_GetManPwd information disclosure5.3
- CVE-2025-7572LB-LINK BL-WR9000 lighttpd.cgi bs_GetHostInfo information disclosure5.3
The record
- Peak rank
- #186 in Jul 2025
- Busiest month shown
- Jul 2025, 5 CVEs
- Months with a KEV entry
- 0 since Jul 2025
- Monthly snapshots
- 1 since 2025