CVE-2026-4228 | LB-LINK BL-WR9000 2.4.9 /goform/set_wifi sub_458754 command injection (EUVD-2026-12371)
A vulnerability, which was classified as critical, was found in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection.
This vulnerability is known as CVE-2026-4228. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.