CVE-2026-19971: LB-Link WR1210M Backup Endpoint backup.cgi main missing authentication
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19971?
The severity of CVE-2026-19971 is medium with a score of 4.7.
How do I fix CVE-2026-19971?
To mitigate CVE-2026-19971, ensure that the LB-Link WR1210M device firmware is updated to the latest version provided by the vendor.
What impact does CVE-2026-19971 have?
CVE-2026-19971 allows unauthorized access to the backup functionality of the LB-Link WR1210M within the local network.
Is CVE-2026-19971 exploitable remotely?
CVE-2026-19971 is not exploitable remotely as the attack can only be carried out within the local network.
Which component is affected by CVE-2026-19971?
CVE-2026-19971 affects the Backup Endpoint function in the /www/cgi-bin/backup.cgi file of the LB-Link WR1210M.