Executive brief
The B-Link X-PRO WiFi router contains hardcoded administrative credentials in its firmware, allowing attackers to gain unauthorized root access to the device remotely. An attacker with knowledge of these credentials can take full control of the router, potentially intercepting network traffic, modifying network settings, and pivoting attacks into the customer's local network and connected devices.
Technical details
This vulnerability involves hardcoded root credentials embedded in the router firmware, stored or accessible via the /etc/shadow file. The vulnerability is triggered through manipulation of an unspecified function that exposes these credentials. While remote exploitation is possible, the attack requires a higher degree of complexity and is considered difficult to execute, though a proof-of-concept exploit is publicly available. The vendor (B-Link/LB-LINK) was contacted early in the disclosure process but did not respond or provide patches. An attacker with access to these hardcoded credentials can authenticate as root and gain complete control of the device.
Affected products
- B-Link X-PRO 1.0.22-20231206
Timeline
- 2026-06-26: disclosed
- 2026-08-15: advisory