A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath of the file /goform/set_delshrpath_cfg of the component Web Management Interface. The manipulation of the argument Type results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 25 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Lb-link bl-ac2100 Firmware
Weaknesses CWE-787
CPEs cpe:2.3:h:lb-link:bl-ac2100:-:*:*:*:*:*:*:*
cpe:2.3:o:lb-link:bl-ac2100_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lb-link bl-ac2100 Firmware

Mon, 22 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Lb-link
Lb-link bl-ac2100
Vendors & Products Lb-link
Lb-link bl-ac2100

Mon, 22 Sep 2025 00:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath of the file /goform/set_delshrpath_cfg of the component Web Management Interface. The manipulation of the argument Type results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Title B-Link BL-AC2100 Web Management set_delshrpath_cfg delshrpath stack-based overflow
Weaknesses CWE-119
CWE-121
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-22T00:02:07.094Z

Updated: 2025-09-22T00:02:07.094Z

Reserved: 2025-09-21T08:26:43.760Z

Link: CVE-2025-10773

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-09-22T01:15:35.810

Modified: 2025-09-25T20:09:53.693

Link: CVE-2025-10773

cve-icon Redhat

No data.