Impact
The vulnerability lies in hard‑coded credentials stored in the /etc/config/easycwmp configuration file of LB‑LINK X‑PRO. Attackers can exploit the exposed default credentials to authenticate to the device remotely, granting them full control of the system. The weakness is identified as CWE‑259 (Hard‑Coded Passwords) and CWE‑798 (Use of Hard‑Coded Credentials), indicating that invisible secret data is embedded in the firmware. Because the attacker can simply use the known credentials, the impact is the ability to execute arbitrary commands and potentially compromise the entire network that the device serves.
Affected Systems
Affected product: LB‑LINK X‑PRO, version 1.0.22‑20231206.
Risk and Exploitability
The CVSS score of 9.2 reflects a high‑severity vulnerability that enables remote execution. EPSS is not available, and the issue is not listed in CISA KEV, but the public release of the exploit makes the risk materialized. The attack vector is remote, likely via the TR‑069 remote management interface that the device exposes; an attacker only needs network access to the device to leverage the hard‑coded credentials. Although the exploit is reported as difficult, the fact that it has been publicly released indicates that skilled adversaries can realize it, posing a significant threat to any network that uses the vulnerable firmware.
OpenCVE Enrichment