Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-12387— Denial of Service in Pix-Link LV-WR21Q

Quick assessment

Affected
Pix-Link LV-WR21Q
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Pix-Link LV-WR21Q是中国Pix-Link公司的一款无线路由器。 Pix-Link LV-WR21Q存在代码问题漏洞,该漏洞源于语言模块处理不当,可能导致远程攻击者通过特制HTTP POST请求触发拒绝服务。

AI Predicted 5.3 Difficulty: Easy EPSS 0.63% · P48

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-12387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial of Service in Pix-Link LV-WR21Q
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service (DoS) by sending a specially crafted HTTP POST request containing non-existing language parameter. This renders the server unable to serve correct lang.js file, which causes administrator panel to not work, resulting in DoS until the language settings is reverted to a correct value. The Denial of Service affects only the administrator panel and does not affect other router functionalities. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对因果或异常条件的不恰当检查
Source: CVE Program / CVE List V5
Vulnerability Title
Pix-Link LV-WR21Q 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pix-Link LV-WR21Q是中国Pix-Link公司的一款无线路由器。 Pix-Link LV-WR21Q存在代码问题漏洞,该漏洞源于语言模块处理不当,可能导致远程攻击者通过特制HTTP POST请求触发拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Pix-Link LV-WR21Q V108_108 -
Pix-Link WR21Q V108_108 -

II. Public POCs for CVE-2025-12387

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-12387

登录查看更多情报信息。

Security Blog Posts for CVE-2025-12387 (1)

Vendor Pages for CVE-2025-12387 (1)

Other References for CVE-2025-12387 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-12387

No comments yet


Leave a comment