CVE-2026-19901: Hard-coded Credentials in LB-LINK X-PRO
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability involves hard-coded credentials embedded in an unknown function within the /etc/config/easycwmp file of LB-LINK X-PRO version 1.0.22-20231206. The presence of these fixed credentials enables remote attackers to gain unauthorized access without needing privileges or user interaction. The attack complexity is high, indicating exploitation is difficult but feasible. Although the vendor was notified early, there has been no response or patch released. Public exploit code is available, which may facilitate attacks against affected devices.
Potential Impact
Successful exploitation allows remote attackers to authenticate using hard-coded credentials, potentially leading to unauthorized access to the device. Given the critical CVSS score of 9.2 and the lack of vendor response, affected devices remain at high risk. The vulnerability could compromise device confidentiality, integrity, and availability depending on attacker actions post-access.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Since the vendor has not responded and no fixes are published, users should consider mitigating risk by isolating affected devices from untrusted networks and monitoring for suspicious activity. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-19901: Hard-coded Credentials in LB-LINK X-PRO
Description
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 9.2critical
Affected software
pkg:github/lb-link/x-procpe:2.3:a:lb-link:x-pro:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves hard-coded credentials embedded in an unknown function within the /etc/config/easycwmp file of LB-LINK X-PRO version 1.0.22-20231206. The presence of these fixed credentials enables remote attackers to gain unauthorized access without needing privileges or user interaction. The attack complexity is high, indicating exploitation is difficult but feasible. Although the vendor was notified early, there has been no response or patch released. Public exploit code is available, which may facilitate attacks against affected devices.
Potential Impact
Successful exploitation allows remote attackers to authenticate using hard-coded credentials, potentially leading to unauthorized access to the device. Given the critical CVSS score of 9.2 and the lack of vendor response, affected devices remain at high risk. The vulnerability could compromise device confidentiality, integrity, and availability depending on attacker actions post-access.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Since the vendor has not responded and no fixes are published, users should consider mitigating risk by isolating affected devices from untrusted networks and monitoring for suspicious activity. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-14T19:11:26.544Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a80a150bf8831d539723291
Added to database: 08/15/2026, 17:26:40 UTC
Last enriched: 08/23/2026, 13:10:36 UTC
Last updated: 09/06/2026, 22:52:08 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.