Hard-Coded Credentials Vulnerability in LB-LINK X-PRO Router
CVE-2026-19900
Key Information:
Badges
What is CVE-2026-19900?
A significant security vulnerability has been discovered in the LB-LINK X-PRO router, specifically in version 1.0.22-20231206. This issue pertains to an unknown function within the /etc/shadow file that exposes hard-coded credentials. Attackers can exploit this vulnerability remotely, allowing access to sensitive information. Although the complexity of the attack is considered high, public exploitation methods are available, which may pose a risk to users. It is important to take proactive measures in securing this device, especially given the vendor's lack of response to the initial disclosure.
Affected Version(s)
X-PRO 1.0.22-20231206
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
