Vulnerability record · CVE-2023-26801 · published 26 March 2023
CVE-2023-26801: LB-LINK Wireless Routers Command Injection in set_LimitClient_cfg
Lb Link · Bl Lte300 Firmware
Multiple LB-LINK router models (BL-AC1900, BL-WR9000, BL-X26, BL-LTE300) contain a command injection flaw in the /goform/set_LimitClient_cfg endpoint via the mac, time1, and time2 parameters. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on the device, and public exploit code exists. It matters because these routers are often internet-facing and can be conscripted into botnets.
Description
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS score is 9.8 (critical), public exploit code exists, and the flaw is actively exploited in the wild to spread Mirai botnet.
What it is
Multiple LB-LINK router models (BL-AC1900, BL-WR9000, BL-X26, BL-LTE300) contain a command injection flaw in the /goform/set_LimitClient_cfg endpoint via the mac, time1, and time2 parameters. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on the device, and public exploit code exists. It matters because these routers are often internet-facing and can be conscripted into botnets.
Impact
An attacker can execute arbitrary system commands with the privileges of the web server, leading to full device compromise. This enables data theft, persistent backdoor installation, and use of the router in further attacks such as DDoS or botnet recruitment.
Attack surface
The flaw is reachable over the network via HTTP requests to the /goform/set_LimitClient_cfg endpoint. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code is available (reference tagged Exploit), and EPSS indicates a high probability of exploitation (0.69663, 99.3rd percentile). The CVE is not listed in CISA KEV, but Akamai research reports it being exploited to spread Mirai botnet.
What to do
- Apply firmware updates from LB-LINK for the affected models as soon as they are available.
- If no patch exists, isolate affected routers behind a firewall and restrict access to the web management interface from untrusted networks.
- Disable remote administration and UPnP on the router if not strictly needed.
- Monitor vendor advisories and replace end-of-life devices that no longer receive security updates.
Detection
- Inspect HTTP requests to /goform/set_LimitClient_cfg for suspicious characters (e.g., ;, |, $, `) in the mac, time1, and time2 parameters.
- Monitor outbound traffic from routers for connections to known Mirai C2 servers or unusual destinations.
- Check router logs for unexpected command execution or process creation events if logging is available.
- Use network intrusion detection signatures for command injection attempts targeting this endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-26801 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-26801), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.