CVE-2026-19900: LB-LINK X-PRO shadow hard-coded credentials
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19900?
CVE-2026-19900 has a high severity score of 8.1.
How do I fix CVE-2026-19900?
To resolve CVE-2026-19900, update the LB-LINK X-PRO software to the latest version where the hard-coded credentials issue is patched.
What impact does CVE-2026-19900 have on my system?
CVE-2026-19900 allows remote attackers to exploit hard-coded credentials, potentially gaining unauthorized access to your system.
Is CVE-2026-19900 remotely exploitable?
Yes, CVE-2026-19900 can be exploited remotely due to the nature of the vulnerability.
What is the attack complexity for CVE-2026-19900?
The attack complexity for CVE-2026-19900 is classified as high, meaning significant effort is required to successfully exploit it.