Impact
The flaw resides in LB‑LINK X‑PRO 1.0.22‑20231206, specifically an undocumented function that manipulates the /etc/shadow file and leaks hard‑coded credentials. The result is that an attacker who can reach the device can authenticate with valid credentials without knowing the original password, thereby gaining full control over the system. This credential‑hardcoding weakness is identified as CWE‑259 and CWE‑798 and compromises confidentiality, integrity, and availability of the device.
Affected Systems
LB‑LINK X‑PRO 1.0.22‑20231206 is the only version documented to be vulnerable. No other products or vendor versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity, and the vulnerability is publicly available, albeit with a high attack complexity and classified as difficult to exploit. The EPSS score is not available, and the issue is not yet cataloged in KEV. Nevertheless, the presence of hard‑coded credentials suggests a favorable exploitation window, especially since the attack can be initiated remotely and the vendor has not issued a fix. Attackers with remote network access to the device represent the highest risk vector.
OpenCVE Enrichment