LB-LINK vulnerabilities
3 CVEs tracked
LB-LINK appears in our reports primarily concerning critical vulnerabilities in its X-PRO and WR1210M models. The main issues revolve around hard-coded credentials and missing authentication flaws discovered in these devices. Key CVEs to focus on include CVE-2026-19900, CVE-2026-19901 (hard-coded credentials in system configuration files) and CVE-2026-19971 (missing authentication for the backup endpoint within the local network). Defenders should urgently apply patches for these specific versions and restrict access to remote management interfaces.
Azərbaycanca: LB-LINK hesabatlarımızda əsasən X-PRO və WR1210M modellərində ciddi zəifliklərlə bağlı görünür. Bu cihazlarda aşkarlanan kritik problemlər sərt kodlaşdırılmış etimadnamələr (hard-coded credentials) və autentifikasiya çatışmazlığı ilə bağlıdır. Diqqət edilməli əsas CVE-lər bunlardır: CVE-2026-19900, CVE-2026-19901 (sistem konfiqurasiya fayllarında sərt kodlaşdırılmış etimadnamələr) və CVE-2026-19971 (lokal şəbəkədə autentifikasiya olmadan ehtiyat nüsxə endpointinə giriş). Müdafiəçilər bu cihazlar üçün təcili yamaqları tətbiq etməli, xüsusilə uzaqdan idarəetmə interfeyslərini məhdudlaşdırmalıdır.
This vendor's CVEs3
This hub is built from skopnix's own reporting on LB-LINK: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.