CVE-2023-26801

CRITICAL

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time...

Affects 8 products across 1 vendor.

BCS7.84
CVSS 3.19.8
EPSS69.7%
Percentile99th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-77: Command Injection

Attacker injects operating system commands through application inputs passed to a shell or system call.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-77
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-77
CAPEC-15 Command Delimiters
via CWE-77
CAPEC-40 Manipulating Writeable Terminal Devices
via CWE-77
CAPEC-75 Manipulating Writeable Configuration Files
via CWE-77
Show all 8
via CWE-77
via CWE-77
via CWE-77

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical command injection vulnerability exists in multiple LB-LINK router models, allowing attackers to execute arbitrary commands on the device.

BSID: BS-2023-GLOBAL-060504-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-26801?
A critical command injection vulnerability exists in multiple LB-LINK router models, allowing attackers to execute arbitrary commands on the device.
What is the CVSS score for CVE-2023-26801?
CVE-2023-26801 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 69.7%.
Is CVE-2023-26801 actively exploited?
No confirmed active exploitation of CVE-2023-26801 as of 2026-05-30.
How do I remediate CVE-2023-26801?
Priority: IMMEDIATE.
What systems are affected by CVE-2023-26801?
CVE-2023-26801 affects: Lb-Link, Lb-Link, Lb-Link, Lb-Link, Lb-Link, Lb-Link, Lb-Link, Lb-Link.
Vulnerability Details
CVE IDCVE-2023-26801
BSIDBS-2023-GLOBAL-060504-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2023-03-26
Last Modified2025-05-05
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is present in the /goform/set_LimitClient_cfg endpoint, where the mac, time1, and time2 parameters are not properly sanitized, leading to command injection.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Lb-Link Bl-Lte300 Firmware
Lb-Link Bl-Lte300
Lb-Link Bl-X26 Firmware
Lb-Link Bl-X26
Lb-Link Bl-Wr9000 Firmware
Lb-Link Bl-Wr9000
Lb-Link Bl-Ac1900 Firmware
Lb-Link Bl-Ac1900
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 1257 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash9ea766731015bdcf8fe980a6d8fc1d37d6f1b6051a347d051508f7d305a0bffa02b9838d31cd3c01616188abdc3f9079a70185a99ffe396ec2be130158fafe5b
Related CVEs affecting Lb-Link
CVE-2024-33375 9.8 LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext ... CVE-2025-1609 9.8 A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified ... CVE-2024-51431 9.8 LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/sha... CVE-2025-1608 9.8 A vulnerability, which was classified as critical, was found in LB-LINK AC190... CVE-2025-1610 9.8 A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as cr...
View all Lb-Link CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →