BL vendor intelligence
BL Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting BL products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 11
- Known exploited vulnerabilities affecting BL products
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 6
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- BL KEVs with sensor-observed exploitation activity
The catalog gap matters for BL exposure
Six of the eleven exploited BL CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 55% of this vendor portfolio.
- 45%
- Covered by CISA
- 55%
- Beyond CISA
- 7
- Product families
Attested BL CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-18577
Incomplete patch leads to administrative account takeover |
N-central | Confirmed | In CISA | 03 Aug 2026 |
|
CVE-2026-18556
Unauthenticated administrative account takeover |
N-central | Confirmed | In CISA | 01 Aug 2026 |
|
CVE-2025-9316
N-central unauthenticated sessionID generation |
N-central | High | Beyond CISA | 03 Jun 2026 |
|
CVE-2020-35580
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files... |
SearchBlox | High | Beyond CISA | 14 Jul 2025 |
|
CVE-2025-8876
Command Injection Vulnerability |
N-central | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-8875
Insecure Deserialization Vulnerability |
N-central | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-45988
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4... |
Blink routers | High | Beyond CISA | 13 Jun 2025 |
|
CVE-2025-32814
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. |
NETMRI | High | Beyond CISA | 22 May 2025 |
|
CVE-2025-0994
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization... |
Cityworks, Cityworks (with office companion) | Confirmed | In CISA | 07 Feb 2025 |
|
CVE-2025-29063
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to... |
AC2100 | High | Beyond CISA | 02 Apr 2025 |
|
CVE-2022-32409
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers... |
i3geo | High | Beyond CISA | 14 Jul 2022 |
No BL CVEs match this search or filter.
Showing 11 of 11 BL known exploited vulnerabilities.
Recurring weakness patterns
Authentication bypass using an alternate path or channel, limitation, and deserialization account for six mapped occurrences across this BL KEV portfolio.
CWE-288
Authentication Bypass Using an Alternate Path or Channel
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-502
Deserialization of Untrusted Data
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-20
Improper Input Validation
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-1284
Improper Validation of Specified Quantity in Input
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.