Impact
The vulnerability resides in the main function of /www/cgi-bin/backup.cgi on LB-Link WR1210M firmware 1.0.3. An attacker can manipulate the request to bypass authentication, allowing them to access the backup interface without credentials. This provides the potential to download or modify configuration backups, exposing sensitive network information.
Affected Systems
This flaw affects the LB-Link WR1210M model running firmware version 1.0.3. No other product or version information is documented.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of risk. While the EPSS score is not available, the vulnerability is also not listed in the KEV catalog. The likely attack vector is a local network attacker able to send crafted requests to the device, so compromise is limited to hosts within the same LAN segment. No public exploit has been found, but the absence of an authentication check means that any local user can exploit it.
OpenCVE Enrichment