Impact
The vulnerability lies in the sub_458754 function of the /goform/set_wifi handler. An attacker can supply crafted input that is not properly sanitized, leading to arbitrary command injection on the device, as evidenced by public exploits. The issue falls under CWE‑74 and CWE‑77.
Affected Systems
The flaw impacts LB‑LINK BL‑WR9000 routers with firmware version 2.4.9. Based on the description, the likely attack vector is remote interaction with the router’s web interface, which would allow execution of commands on the device’s operating system.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, while the EPSS score of 9% indicates a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers with remote access to the web interface could exploit, and the actual threat depends on how exposed the device is and the protections applied by the administrator.
OpenCVE Enrichment