Impact
The vulnerability lies in the sub_458754 function of the /goform/set_wifi handler. An attacker can supply crafted input that is not properly sanitized, leading to arbitrary command injection on the device, as evidenced by public exploits. The issue falls under CWE‑74 and CWE‑77.
Affected Systems
The flaw impacts LB‑LINK BL‑WR9000 routers running firmware version 2.4.9. It can be triggered remotely by interacting with the router’s web interface, allowing the execution of commands on the device’s operating system.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, while the EPSS score of 1% suggests a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. Attackers with remote access to the web interface could exploit the flaw, but because no official patch or workaround is available, the actual threat depends on how exposed the device is and the protections applied by the administrator.
OpenCVE Enrichment