CVE-2026-19901 PUBLISHED

LB-LINK X-PRO easycwmp hard-coded credentials

Assigner: VulDB
Reserved: 14.08.2026 Published: 15.08.2026 Updated: 15.08.2026

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 9.2

Product Status

Vendor LB-LINK
Product X-PRO
Versions
  • Version 1.0.22-20231206 is affected

Credits

  • Yun Zhang (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Hard-coded Credentials CWE
  • Use of Hard-coded Password CWE