CVE-2026-19901

8.1

LB-LINK · X-PRO

LB-LINK X-PRO 1.0.22-20231206 contains hard-coded credentials, allowing unauthenticated remote access to management interfaces.

Executive summary

The presence of hard-coded credentials in the LB-LINK X-PRO device poses a critical risk of unauthorized remote administration and system compromise.

Vulnerability

This vulnerability involves the use of hard-coded credentials (CWE-798, CWE-259) for remote management functions, which allows an unauthenticated attacker to gain full administrative access to the device.

Business impact

Successful exploitation allows an attacker to bypass authentication mechanisms entirely, leading to unauthorized control over the device. Given the CVSS score of 8.1, this is a high-severity issue that could result in complete loss of confidentiality and integrity for the affected network segment, potentially facilitating further lateral movement within the infrastructure.

Remediation

Immediate Action: Since no official patch is currently identified, isolate the device from the public internet immediately and disable remote management features.

Proactive Monitoring: Review network access logs for unusual traffic targeting management ports and monitor for unauthorized login attempts or configuration changes.

Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict management interface access to trusted, internal IP addresses only.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

This vulnerability represents a significant security oversight that exposes the device to complete compromise. Organizations must prioritize restricting network access to the affected hardware immediately and monitor for vendor-released firmware updates to address the underlying hard-coded credential issue.

More LB-LINK CVEs