← Vulnerability feed

Vulnerability record · CVE-2023-26801 · published 26 March 2023

CVE-2023-26801: LB-LINK Wireless Routers Command Injection in set_LimitClient_cfg

Lb Link · Bl Lte300 Firmware

Multiple LB-LINK router models (BL-AC1900, BL-WR9000, BL-X26, BL-LTE300) contain a command injection flaw in the /goform/set_LimitClient_cfg endpoint via the mac, time1, and time2 parameters. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on the device, and public exploit code exists. It matters because these routers are often internet-facing and can be conscripted into botnets.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.7% CWE-77 · Command injection
9.8CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS score is 9.8 (critical), public exploit code exists, and the flaw is actively exploited in the wild to spread Mirai botnet.

What it is

Multiple LB-LINK router models (BL-AC1900, BL-WR9000, BL-X26, BL-LTE300) contain a command injection flaw in the /goform/set_LimitClient_cfg endpoint via the mac, time1, and time2 parameters. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on the device, and public exploit code exists. It matters because these routers are often internet-facing and can be conscripted into botnets.

Impact

An attacker can execute arbitrary system commands with the privileges of the web server, leading to full device compromise. This enables data theft, persistent backdoor installation, and use of the router in further attacks such as DDoS or botnet recruitment.

Attack surface

The flaw is reachable over the network via HTTP requests to the /goform/set_LimitClient_cfg endpoint. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code is available (reference tagged Exploit), and EPSS indicates a high probability of exploitation (0.69663, 99.3rd percentile). The CVE is not listed in CISA KEV, but Akamai research reports it being exploited to spread Mirai botnet.

What to do

  • Apply firmware updates from LB-LINK for the affected models as soon as they are available.
  • If no patch exists, isolate affected routers behind a firewall and restrict access to the web management interface from untrusted networks.
  • Disable remote administration and UPnP on the router if not strictly needed.
  • Monitor vendor advisories and replace end-of-life devices that no longer receive security updates.

Detection

  • Inspect HTTP requests to /goform/set_LimitClient_cfg for suspicious characters (e.g., ;, |, $, `) in the mac, time1, and time2 parameters.
  • Monitor outbound traffic from routers for connections to known Mirai C2 servers or unusual destinations.
  • Check router logs for unexpected command execution or process creation events if logging is available.
  • Use network intrusion detection signatures for command injection attempts targeting this endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26801 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.4CVE-2026-4226Lb-link bl-wr9000 firmware memory buffer overflow vulnerabilityA weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /goform/get_virtual_cfg. Execu…EPSS 1.1%7.4CVE-2026-4227Lb-link bl-wr9000 firmware memory buffer overflow vulnerabilityA security vulnerability has been detected in LB-LINK BL-WR9000 2.4.9. The impacted element is the function sub_44D844 of the file /goform/get_hidess…EPSS 1.1%2.1CVE-2026-4228Lb-link bl-wr9000 firmware injection vulnerabilityA vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results …EPSS 8.9%2.1CVE-2025-9580Lb-link bl-x26 firmware command injection vulnerabilityA security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the compone…EPSS 6.7%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2023-26801), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.