CVE-2026-19900
Received Received - Intake

Hard-Coded Credentials in LB-LINK X-PRO Firmware

Vulnerability report for CVE-2026-19900, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulDB

Description

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lb-link x-pro 1.0.22-20231206

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in LB-LINK X-PRO 1.0.22-20231206 where hard-coded credentials are present due to an issue in an unknown function related to the file /etc/shadow. The attack requires a high level of complexity and is considered difficult to exploit, though a public exploit is available.

Detection Guidance

This vulnerability involves hard-coded credentials in LB-LINK X-PRO 1.0.22-20231206 related to the /etc/shadow file. Detection may require checking for default or weak credentials in device configurations or firmware. Inspect network devices for unusual login attempts or unauthorized access. Review system logs for suspicious activity linked to the device.

Impact Analysis

An attacker could remotely exploit this vulnerability to gain unauthorized access to the system due to the hard-coded credentials. This could lead to full compromise of the device, including reading or modifying sensitive data, or executing arbitrary commands.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations using this device may fail compliance audits due to inadequate security controls and hard-coded credentials.

Mitigation Strategies

Immediately check for hard-coded credentials in /etc/shadow on LB-LINK X-PRO devices. Update firmware if available or isolate affected systems from the network. Monitor for unusual remote access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19900. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart