Hard-Coded Credentials Vulnerability in LB-LINK X-PRO Router
CVE-2026-19900

9.2CRITICAL

Key Information:

Vendor

Lb-link

Status
Vendor
CVE Published:
15 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-19900?

A significant security vulnerability has been discovered in the LB-LINK X-PRO router, specifically in version 1.0.22-20231206. This issue pertains to an unknown function within the /etc/shadow file that exposes hard-coded credentials. Attackers can exploit this vulnerability remotely, allowing access to sensitive information. Although the complexity of the attack is considered high, public exploitation methods are available, which may pose a risk to users. It is important to take proactive measures in securing this device, especially given the vendor's lack of response to the initial disclosure.

Affected Version(s)

X-PRO 1.0.22-20231206

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yun Zhang (VulDB User)
VulDB CNA Team
.