/Vulnerability Library

LB-LINK Routers - Unauthenticated Command Injection

CVE-2026-19900
Verified

Description

LB-LINK X-PRO 1.0.22-20231206 contains a hardcoded credentials vulnerability caused by manipulation of an unknown function in /etc/shadow, letting remote attackers use hardcoded credentials, exploit requires high complexity

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

bl-wr9000_firmware

Published Date

August 18, 2026

Template Author

0x_akoko

CVE-2026-19900.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-19900
CWE ID:
cwe-77

References

https://github.com/glkfc/IoT-Vulnerability/blob/main/LB-LINK/LB-LINK_cmd%20Indicates%20the%20unauthorized%20command%20injection/The%20LB-LINK_cmd%20command%20is%20used%20to%20inject%20information.mdhttps://nvd.nist.gov/vuln/detail/CVE-2026-19900

Remediation Steps

Update to the latest version or contact vendor for a patch.