Authentication Flaw in LB-Link BL-CPE300M AX300 4G LTE Router
CVE-2025-57278

Currently unrated

Key Information:

Vendor

LB-Link

Vendor
CVE Published:
9 September 2025

What is CVE-2025-57278?

The LB-Link BL-CPE300M AX300 4G LTE Router is susceptible to an authentication bypass due to improper session handling. Once a user authenticates from a given IP address, the router fails to enforce appropriate identity verification for subsequent clients using the same IP. This flaw allows malicious actors to gain administrative access without credentials, by simply spoofing the IP of a previously authenticated user. There are no mechanisms like session tokens or unique identifiers implemented, leaving systems vulnerable to unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.