Hard-Coded Credentials in LB-LINK X-PRO
LB-LINK X-PRO version 1.0.22-20231206 contains hard-coded credentials in /etc/config/easycwmp, allowing potential remote unauthorized access via publicly available exploits.
CVE search metadata
CVE search record: CVE-2026-19901. Severity: high. CVSS: 8.1. KEV: no. Product: X-PRO (1.0.22-20231206). Brief: Hard-Coded Credentials in LB-LINK X-PRO. Brief link: https://feed.craftedsignal.io/briefs/2026-08-lb-link-hardcoded-creds/
A vulnerability identified as CVE-2026-19901 affects LB-LINK X-PRO version 1.0.22-20231206. The flaw resides within the /etc/config/easycwmp configuration file, which contains hard-coded credentials. This configuration flaw allows for remote exploitation of the device. Although the vendor was notified of the disclosure, they have not provided a response or a patch. Publicly available exploit code exists, increasing the risk of unauthorized access to affected network infrastructure. While the attack is characterized as highly complex and difficult to execute, the presence of hard-coded credentials in internet-facing network devices presents a significant security risk for organizations deploying these routers.
Impact
Successful exploitation of this vulnerability allows an unauthorized remote actor to gain administrative or privileged access to the affected network device. This can lead to total device compromise, internal network reconnaissance, and traffic interception. As this affects network-layer hardware, impacted organizations face a risk of full network segment exposure.
Recommendation
- Immediately isolate affected LB-LINK X-PRO devices from the public internet.
- Audit network infrastructure to identify devices running firmware version 1.0.22-20231206.
- Implement strict firewall rules limiting access to administrative interfaces (including CWMP/TR-069 management ports) to trusted internal management subnets only.
- Monitor network traffic for unusual authentication attempts targeting embedded device management services.
Immediate actions
Isolate affected LB-LINK devices from public internet egress
Mitigations
Restrict access to management interfaces on affected network hardware
CVE-2026-19901