Description
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-15
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in hard‑coded credentials stored in the /etc/config/easycwmp configuration file of LB‑LINK X‑PRO. Attackers can exploit the exposed default credentials to authenticate to the device remotely, granting them full control of the system. The weakness is identified as CWE‑259 (Hard‑Coded Passwords) and CWE‑798 (Use of Hard‑Coded Credentials), indicating that invisible secret data is embedded in the firmware. Because the attacker can simply use the known credentials, the impact is the ability to execute arbitrary commands and potentially compromise the entire network that the device serves.

Affected Systems

Affected product: LB‑LINK X‑PRO, version 1.0.22‑20231206.

Risk and Exploitability

The CVSS score of 9.2 reflects a high‑severity vulnerability that enables remote execution. EPSS is not available, and the issue is not listed in CISA KEV, but the public release of the exploit makes the risk materialized. The attack vector is remote, likely via the TR‑069 remote management interface that the device exposes; an attacker only needs network access to the device to leverage the hard‑coded credentials. Although the exploit is reported as difficult, the fact that it has been publicly released indicates that skilled adversaries can realize it, posing a significant threat to any network that uses the vulnerable firmware.

Generated by OpenCVE AI on August 15, 2026 at 18:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Change or remove the hard‑coded credentials in /etc/config/easycwmp and set strong, unique passwords for all administrative accounts.
  • If an official firmware update that removes the vulnerability becomes available, install it immediately.
  • Disable or restrict the TR‑069 remote management service if it is not essential for your environment to prevent unauthorized remote access.

Generated by OpenCVE AI on August 15, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title LB-LINK X-PRO easycwmp hard-coded credentials
First Time appeared Lb-link
Lb-link x-pro
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:lb-link:x-pro:*:*:*:*:*:*:*:*
Vendors & Products Lb-link
Lb-link x-pro
References
Metrics cvssV2_0

{'score': 7.6, 'vector': 'AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-15T17:15:07.700Z

Reserved: 2026-08-14T19:11:26.544Z

Link: CVE-2026-19901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T18:16:24.830

Modified: 2026-08-15T18:16:24.830

Link: CVE-2026-19901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T18:30:12Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials