Authentication Flaw in LB-Link BL-CPE300M AX300 4G LTE Router
CVE-2025-57278

8.8HIGH

Key Information:

Vendor

LB-Link

Vendor
CVE Published:
9 September 2025

What is CVE-2025-57278?

The LB-Link BL-CPE300M AX300 4G LTE Router is susceptible to an authentication bypass due to improper session handling. Once a user authenticates from a given IP address, the router fails to enforce appropriate identity verification for subsequent clients using the same IP. This flaw allows malicious actors to gain administrative access without credentials, by simply spoofing the IP of a previously authenticated user. There are no mechanisms like session tokens or unique identifiers implemented, leaving systems vulnerable to unauthorized access.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.