Sceawere

Vulnerability Detail

CVE-2026-19901UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LB-LINK X-PRO Hard-Coded Credentials

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
4h ago
Vendor
LB-LINK
Product
X-PRO
Attack Type
Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-15T18:16:24.830Z",
  "pubdate": "2026-08-15T18:16:24.830Z",
  "executiveSummary": "A security flaw has been identified in the LB-LINK X-PRO firmware version 1.0.22-20231206, specifically within the /etc/config/easycwmp configuration file. The vulnerability involves the presence of hard-coded credentials, exposing the device to unauthorized access and potential administrative compromise. This security defect impacts the confidentiality and integrity of the affected networking equipment.\nThe vulnerability allows remote attackers to leverage the embedded credentials to bypass authentication mechanisms. Although the attack complexity is considered high and the exploitability is reported as difficult, a public exploit has already been released, increasing the risk of opportunistic exploitation. The vendor was contacted early regarding the disclosure but failed to provide any response or patch.\nOrganizations deploying the affected LB-LINK X-PRO systems face significant risk if devices are exposed to wide-area networks or untrusted network segments. Successful exploitation grants unauthorized actors access to the device management interfaces or TR-069 CPE WAN Management Protocol configurations via easycwmp.\nGiven the lack of vendor response and patch availability, immediate defensive postures must rely on network segmentation, perimeter controls, and disabling unnecessary remote management services to mitigate the exposure of these hard-coded credentials.",
  "technicalDetails": "The vulnerability resides within the configuration file located at /etc/config/easycwmp on LB-LINK X-PRO version 1.0.22-20231206. The root cause of the issue is the static embedding of sensitive authentication data, such as usernames and passwords, directly into the firmware configuration files rather than utilizing dynamically generated secrets or enforcing strong, user-defined credentials upon initial provisioning.\nThe vulnerable component is the easycwmp service configuration, which handles the CPE WAN Management Protocol (TR-069) for remote device management and auto-configuration server interactions. Because the credentials are hard-coded into the system filesystem, any entity with access to the firmware image or the ability to query the device interfaces can extract or utilize these static secrets.\nThe attack vector is network-accessible, allowing remote adversaries to launch attacks against the exposed service endpoints. While exploitation requires high complexity and is classified as difficult, the public availability of an exploit script or proof-of-concept lowers the operational threshold for threat actors to execute the attack successfully.\nThe step-by-step attack flow involves an external adversary identifying an exposed LB-LINK X-PRO device connected to the network. The attacker targets the easycwmp service interface or associated management daemons. By leveraging the known hard-coded credentials embedded within /etc/config/easycwmp, the adversary authenticates to the system without requiring prior access or brute-force mechanisms. Upon successful authentication, the attacker gains unauthorized administrative or protocol-level access, potentially enabling full control over the CPE device, manipulation of TR-069 parameters, and further pivoting into the local network infrastructure."
}
CVE-2026-19901: LB-LINK X-PRO Hard-Coded Credentials (HIGH Severity, CVSS: 8.1) - Sceawere