CVE-2025-7574

CRITICAL

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/rest...

Affects 0 products across 2 vendors.

BCS7.46
CVSS 3.19.8
CVSS v48.9
EPSS0.7%
Percentile52th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability (CVE-2025-7574) in LB-LINK routers allows remote attackers to perform improper authentication via the /cgi-bin/lighttpd.cgi file in the Web Interface, leading to potential unauthorized access.

BSID: BS-2025-GLOBAL-036719-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-7574?
A critical vulnerability (CVE-2025-7574) in LB-LINK routers allows remote attackers to perform improper authentication via the /cgi-bin/lighttpd.cgi file in the Web Interface, leading to potential unauthorized access.
What is the CVSS score for CVE-2025-7574?
CVE-2025-7574 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.7%.
Is CVE-2025-7574 actively exploited?
No confirmed active exploitation of CVE-2025-7574 as of 2026-05-30.
How do I remediate CVE-2025-7574?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-7574?
CVE-2025-7574 affects: Lb-Link, Lighttpd.
Vulnerability Details
CVE IDCVE-2025-7574
BSIDBS-2025-GLOBAL-036719-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-07-14
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web Interface. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely by sending specially crafted requests to the /cgi-bin/lighttpd.cgi endpoint, which handles the reboot/restore functionality. This can lead to improper authentication, potentially allowing unauthorized access to the device.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Lb-Link —
Lighttpd —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 401 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashab415b309caf27b2ebead0dcec22a86ef17549a2f8f5d43ae187125917be2e3be03f20f8b75f87e1d42ba6093860829c8507cfb1ddc10f9471d099e2bfdb37f9
Related CVEs affecting Lb-Link
CVE-2025-1608 9.8 A vulnerability, which was classified as critical, was found in LB-LINK AC190... CVE-2023-26801 9.8 LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5... CVE-2024-33375 9.8 LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext ... CVE-2024-51431 9.8 LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/sha... CVE-2025-1609 9.8 A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified ...
View all Lb-Link CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →