Sceawere

Vulnerability Detail

CVE-2026-19971UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LB-Link WR1210M Backup Authentication Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
2h ago
Vendor
LB-Link
Product
WR1210M
Attack Type
Missing Authentication
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-08-17T02:16:41.203Z",
  "pubdate": "2026-08-17T02:16:41.203Z",
  "executiveSummary": "An authentication bypass vulnerability has been identified in the LB-Link WR1210M 1.0.3 router, specifically within the Backup Endpoint component. The flaw resides in the main function of the /www/cgi-bin/backup.cgi binary, which fails to enforce proper authentication controls before processing backup requests. This security deficiency allows unauthorized access to critical administrative functionality exposed via the web interface. The impact of this vulnerability includes the potential exposure of sensitive system configuration data or unauthorized execution of backup-related operations without requiring valid credentials. The attack surface is restricted to the local network, requiring the threat actor to have initial local network access—either via physical connectivity or compromised wireless access—to interact with the device's web administration interface. Exploitation of this flaw undermines the access control boundary of the router, posing a significant risk to network confidentiality and integrity. The vendor was notified of this vulnerability prior to public disclosure but failed to provide any response or official patch.",
  "technicalDetails": "The vulnerability is classified as a missing authentication flaw, occurring due to the absence of robust access control checks within the core execution logic of the targeted binary. The affected component is the Backup Endpoint, specifically mapped to the /www/cgi-bin/backup.cgi script located on the device's embedded filesystem. Upon receiving an HTTP request targeting this Common Gateway Interface (CGI) endpoint, the main function executes the associated routines directly without validating whether the requesting session possesses an authenticated administrative context.\nThe root cause stems from insecure software design practices where sensitive administrative endpoints are exposed without enforcing session validation tokens, cookies, or HTTP authentication headers prior to executing core logic. In a securely implemented architecture, the main function of an administrative CGI binary should perform an explicit check against active session identifiers or credentials stored in the context of the HTTP request. Because this validation is omitted in version 1.0.3, any unauthenticated HTTP client capable of reaching the endpoint can successfully trigger the backup execution routine.\nThe attack flow proceeds as follows: First, the adversary establishes presence within the local network where the LB-Link WR1210M device is deployed. Second, the attacker formulates an HTTP request targeting the absolute path /www/cgi-bin/backup.cgi hosted on the router's web server interface. Third, due to the missing authentication check, the web server passes the request directly to the main function of the vulnerable binary without demanding credentials. Fourth, the binary processes the request and executes the intended backup logic, potentially returning sensitive system configuration files or state data directly to the unauthenticated requester.\nNetwork exposure is strictly constrained to the local network segment, meaning external threat actors cannot directly exploit this vulnerability unless they have already achieved a foothold within the internal network perimeter or bypassed perimeter defenses via pivoting or cross-site scripting vectors. Privilege requirements are effectively non-existent for the execution of the endpoint, allowing an unauthenticated user to interact with functionality that should otherwise be restricted to high-privilege administrators. The post-exploitation impact includes the unauthorized extraction of system backups, which frequently contain sensitive information such as Wi-Fi pre-shared keys, administrative credentials, network topologies, and internal routing configurations, thereby facilitating further compromise of the local network infrastructure."
}
CVE-2026-19971: LB-Link WR1210M Backup Authentication Bypass (MEDIUM Severity, CVSS: 4.7) - Sceawere