What is CVE-2026-19971?
A missing authentication vulnerability was found in the Backup Endpoint of LB-Link WR1210M 1.0.3, specifically in the /www/cgi-bin/backup.cgi file. This allows attackers within the local network to gain unauthorized access to the backup function. The vendor has been notified early about this disclosure.
Azərbaycanca: LB-Link WR1210M 1.0.3 cihazında, /www/cgi-bin/backup.cgi faylındakı Backup Endpoint-in autentifikasiya çatışmazlığı aşkar edilib. Bu zəiflik lokal şəbəkə daxilində olan təcavüzkarlara cihazın ehtiyat nüsxə funksiyasına icazəsiz giriş imkanı verir. İstehsalçı ilə əlaqə saxlanılıb, yamaq gözlənilir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which device is affected by CVE-2026-19971?
This vulnerability affects the LB-Link WR1210M 1.0.3 device.
Where must an attacker be located to exploit CVE-2026-19971?
The attacker must be within the local network.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.