Description
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-15
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in LB‑LINK X‑PRO 1.0.22‑20231206, specifically an undocumented function that manipulates the /etc/shadow file and leaks hard‑coded credentials. The result is that an attacker who can reach the device can authenticate with valid credentials without knowing the original password, thereby gaining full control over the system. This credential‑hard­coding weakness is identified as CWE‑259 and CWE‑798 and compromises confidentiality, integrity, and availability of the device.

Affected Systems

LB‑LINK X‑PRO 1.0.22‑20231206 is the only version documented to be vulnerable. No other products or vendor versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity, and the vulnerability is publicly available, albeit with a high attack complexity and classified as difficult to exploit. The EPSS score is not available, and the issue is not yet cataloged in KEV. Nevertheless, the presence of hard‑coded credentials suggests a favorable exploitation window, especially since the attack can be initiated remotely and the vendor has not issued a fix. Attackers with remote network access to the device represent the highest risk vector.

Generated by OpenCVE AI on August 15, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official firmware update that removes hard‑coded credentials; if no update is available, obtain the latest release and confirm removal of the vulnerable function.
  • Restrict remote administrative access to the device, for example by disabling telnet/ssh/http interfaces or placing the device behind a firewall that only permits trusted IP addresses.
  • Segregate the device on a dedicated network segment and enforce strict access controls to limit exposure to potential attackers.
  • Log and monitor authentication attempts; alert on repeated failures or suspicious activity.

Generated by OpenCVE AI on August 15, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title LB-LINK X-PRO shadow hard-coded credentials
First Time appeared Lb-link
Lb-link x-pro
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:lb-link:x-pro:*:*:*:*:*:*:*:*
Vendors & Products Lb-link
Lb-link x-pro
References
Metrics cvssV2_0

{'score': 7.6, 'vector': 'AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-15T16:45:07.432Z

Reserved: 2026-08-14T19:11:22.504Z

Link: CVE-2026-19900

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T17:16:24.730

Modified: 2026-08-15T17:16:24.730

Link: CVE-2026-19900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T18:30:12Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials