{
    "id": "CVE-2023-26801",
    "published": "2023-03-26 21:15:07",
    "last_modified": "2026-06-17 05:43:49",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-77",
    "description": "LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.",
    "epss_score": "0.69663",
    "epss_percentile": "0.99348",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-09-29 18:17:35",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 69.7% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "lb-link",
            "product": "bl-ac1900"
        },
        {
            "vendor": "lb-link",
            "product": "bl-ac1900_firmware"
        },
        {
            "vendor": "lb-link",
            "product": "bl-lte300"
        },
        {
            "vendor": "lb-link",
            "product": "bl-lte300_firmware"
        },
        {
            "vendor": "lb-link",
            "product": "bl-wr9000"
        },
        {
            "vendor": "lb-link",
            "product": "bl-wr9000_firmware"
        },
        {
            "vendor": "lb-link",
            "product": "bl-x26"
        },
        {
            "vendor": "lb-link",
            "product": "bl-x26_firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://github.com/winmt/my-vuls/tree/main/LB-LINK%20BL-AC1900%2C%20BL-WR9000%2C%20BL-X26%20and%20BL-LTE300%20Wireless%20Routers",
        "https://www.akamai.com/blog/security-research/cve-2023-26801-exploited-spreading-mirai-botnet",
        "https://github.com/winmt/my-vuls/tree/main/LB-LINK%20BL-AC1900%2C%20BL-WR9000%2C%20BL-X26%20and%20BL-LTE300%20Wireless%20Routers"
    ]
}