CVE-2025-7564
7.8LB-LINK · BL-AC3600
The LB-LINK BL-AC3600 router contains hard-coded credentials in the /etc/shadow file, which can be exploited by a local user to gain unauthorized administrative access.
Executive summary
The LB-LINK BL-AC3600 router is vulnerable to a hard-coded credential flaw that allows unauthorized local users to gain administrative control over the device.
Vulnerability
This vulnerability is caused by the presence of hard-coded credentials (CWE-798) within the /etc/shadow system file. Successful exploitation requires local access to the device and enables an attacker to authenticate with elevated privileges.
Business impact
The presence of hard-coded credentials poses a significant risk to the integrity and security of the network infrastructure. With a CVSS score of 7.8, this flaw could allow an attacker with local access to bypass security controls, leading to total compromise of the router. This may result in unauthorized network traffic interception, persistent backdoors, or the complete loss of administrative control over the affected hardware.
Remediation
Immediate Action: As no official patch is currently available from the vendor, administrators should restrict physical and logical access to the device to trusted personnel only.
Proactive Monitoring: Monitor device access logs for unusual login activity or unauthorized attempts to access sensitive system files like /etc/shadow.
Compensating Controls: Implement network segmentation to isolate the affected router from critical internal assets, limiting the potential blast radius of a compromised device.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up by the vulnerability reporter.
Analyst recommendation
Given the severity of this vulnerability and the lack of a vendor-provided patch, immediate mitigation is required. Organizations using the LB-LINK BL-AC3600 should evaluate the necessity of the device in their network architecture and consider replacing it with a supported alternative if the risk to the environment is deemed unacceptable.
More LB-LINK CVEs
Sources
Originally found and disclosed by waiwai24 (VulDB User), per the CVE Program record.
- VDB-316262 | LB-LINK BL-AC3600 shadow hard-coded credentials Vulnerability database entry
- VDB-316262 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #605630 | Blink BL-AC3600 V1.0.22 Hard-coded Credentials Third-party advisory
- Related
- Exploit / PoC