{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lb-link/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-19901"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["X-PRO (1.0.22-20231206)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LB-LINK"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-19901 affects LB-LINK X-PRO version 1.0.22-20231206. The flaw resides within the /etc/config/easycwmp configuration file, which contains hard-coded credentials. This configuration flaw allows for remote exploitation of the device. Although the vendor was notified of the disclosure, they have not provided a response or a patch. Publicly available exploit code exists, increasing the risk of unauthorized access to affected network infrastructure. While the attack is characterized as highly complex and difficult to execute, the presence of hard-coded credentials in internet-facing network devices presents a significant security risk for organizations deploying these routers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthorized remote actor to gain administrative or privileged access to the affected network device. This can lead to total device compromise, internal network reconnaissance, and traffic interception. As this affects network-layer hardware, impacted organizations face a risk of full network segment exposure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate affected LB-LINK X-PRO devices from the public internet.\u003c/li\u003e\n\u003cli\u003eAudit network infrastructure to identify devices running firmware version 1.0.22-20231206.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall rules limiting access to administrative interfaces (including CWMP/TR-069 management ports) to trusted internal management subnets only.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unusual authentication attempts targeting embedded device management services.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T18:20:12Z","date_published":"2026-08-15T18:20:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-lb-link-hardcoded-creds/","summary":"LB-LINK X-PRO version 1.0.22-20231206 contains hard-coded credentials in /etc/config/easycwmp, allowing potential remote unauthorized access via publicly available exploits.","title":"Hard-Coded Credentials in LB-LINK X-PRO","url":"https://feed.craftedsignal.io/briefs/2026-08-lb-link-hardcoded-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - LB-LINK","version":"https://jsonfeed.org/version/1.1"}