Authentication Flaw in LB-Link BL-CPE300M AX300 4G LTE Router
CVE-2025-57278
Currently unrated
What is CVE-2025-57278?
The LB-Link BL-CPE300M AX300 4G LTE Router is susceptible to an authentication bypass due to improper session handling. Once a user authenticates from a given IP address, the router fails to enforce appropriate identity verification for subsequent clients using the same IP. This flaw allows malicious actors to gain administrative access without credentials, by simply spoofing the IP of a previously authenticated user. There are no mechanisms like session tokens or unique identifiers implemented, leaving systems vulnerable to unauthorized access.