Sceawere

Vulnerability Detail

CVE-2026-19900UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LB-LINK X-PRO Hard-Coded Credentials

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
1h ago
Vendor
LB-LINK
Product
X-PRO
Attack Type
Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-15T17:16:24.730Z",
  "pubdate": "2026-08-15T17:16:24.730Z",
  "executiveSummary": "A security vulnerability has been identified in LB-LINK X-PRO version 1.0.22-20231206 involving the use of hard-coded credentials associated with the file /etc/shadow. This flaw allows remote threat actors to bypass standard authentication mechanisms and potentially gain unauthorized administrative access to affected devices.\nThe risk implication is critical, as compromise of the shadow password file typically exposes system authentication hashes, facilitating privilege escalation and full system takeover. Although the vendor was contacted early regarding this disclosure, no response or official patch has been provided.\nAccording to the vulnerability characteristics, the attack can be initiated remotely, but it requires a high degree of complexity and the exploitability is regarded as difficult. However, functional exploit code is publicly available, increasing the likelihood of opportunistic exploitation by malicious actors scanning for vulnerable firmware deployments.",
  "technicalDetails": "The vulnerability resides in LB-LINK X-PRO version 1.0.22-20231206, specifically concerning the handling and exposure of authentication materials within the file /etc/shadow. The root cause of this security defect is the implementation of hard-coded cryptographic credentials or static account configurations embedded directly into the firmware image during the build process.\nThe vulnerable component involves internal system functions or parsing routines that interact with the system authentication database, allowing unauthorized retrieval or misuse of credential material. Because the credentials are hard-coded, they remain persistent across device resets and cannot be altered by administrators through standard configuration interfaces, violating secure credential management best practices.\nRegarding attack vectors and network exposure, the vulnerability is accessible remotely. The attack flow begins with the threat actor identifying an exposed network service or interface that interacts with or leaks the contents of the file /etc/shadow. Utilizing publicly available exploit material, the attacker initiates communication targeting the vulnerable endpoint.\nAlthough the exploitability is classified as difficult and demands a high degree of complexity—potentially requiring precise payload formatting, specific protocol manipulation, or chaining with secondary logic flaws—successful execution bypasses authentication constraints entirely.\nPost-exploitation impact includes the extraction of password hashes from /etc/shadow, enabling offline brute-force or dictionary attacks against user accounts, or direct authentication as a privileged user. This grants the attacker deep persistence, full control over the underlying operating system, and the ability to pivot within the local network or subvert device integrity."
}
CVE-2026-19900: LB-LINK X-PRO Hard-Coded Credentials (HIGH Severity, CVSS: 8.1) - Sceawere