What is CVE-2026-19901?
A security flaw in the /etc/config/easycwmp file of LB-LINK X-PRO 1.0.22-20231206 leads to hard-coded credentials being exposed. This allows highly complex remote attacks on the affected device. Users should await an official patch or temporarily isolate the device from the network.
Azərbaycanca: LB-LINK X-PRO 1.0.22-20231206 qurğusunda /etc/config/easycwmp faylında aşkar edilmiş təhlükəsizlik boşluğu sərt kodlaşdırılmış giriş məlumatlarına (hard-coded credentials) səbəb olur. Bu, uzaqdan mürəkkəb hücumlara imkan yaradır. Qurğu sahibləri istehsalçıdan yeniləmə gözləməli və ya müvəqqəti olaraq cihazı şəbəkədən ayırmalıdır.
Related CVEs
link basis: same weakness class CWE-798; shared vendor: LB-LINK
FAQ2
What type of security vulnerability affects the LB-LINK X-PRO 1.0.22-20231206 device?
The device is affected by hard-coded credentials found in the /etc/config/easycwmp file.
What is recommended for device owners while waiting for an official patch from the manufacturer?
It is recommended to temporarily isolate the device from the network.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.