<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>X-PRO (1.0.22-20231206) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/x-pro-1.0.22-20231206/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 15 Aug 2026 18:20:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/x-pro-1.0.22-20231206/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hard-Coded Credentials in LB-LINK X-PRO</title><link>https://feed.craftedsignal.io/briefs/2026-08-lb-link-hardcoded-creds/</link><pubDate>Sat, 15 Aug 2026 18:20:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-lb-link-hardcoded-creds/</guid><description>LB-LINK X-PRO version 1.0.22-20231206 contains hard-coded credentials in /etc/config/easycwmp, allowing potential remote unauthorized access via publicly available exploits.</description><content:encoded><![CDATA[<p>A vulnerability identified as CVE-2026-19901 affects LB-LINK X-PRO version 1.0.22-20231206. The flaw resides within the /etc/config/easycwmp configuration file, which contains hard-coded credentials. This configuration flaw allows for remote exploitation of the device. Although the vendor was notified of the disclosure, they have not provided a response or a patch. Publicly available exploit code exists, increasing the risk of unauthorized access to affected network infrastructure. While the attack is characterized as highly complex and difficult to execute, the presence of hard-coded credentials in internet-facing network devices presents a significant security risk for organizations deploying these routers.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthorized remote actor to gain administrative or privileged access to the affected network device. This can lead to total device compromise, internal network reconnaissance, and traffic interception. As this affects network-layer hardware, impacted organizations face a risk of full network segment exposure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately isolate affected LB-LINK X-PRO devices from the public internet.</li>
<li>Audit network infrastructure to identify devices running firmware version 1.0.22-20231206.</li>
<li>Implement strict firewall rules limiting access to administrative interfaces (including CWMP/TR-069 management ports) to trusted internal management subnets only.</li>
<li>Monitor network traffic for unusual authentication attempts targeting embedded device management services.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>