Executive brief
LB-LINK X-PRO is a network appliance that uses the easycwmp component for remote TR-069 management. The device contains hard-coded credentials in its configuration file, allowing attackers to gain unauthorized remote access to the device management interface without needing to obtain valid user credentials. This vulnerability permits attackers to remotely manage or compromise the device from the network.
Technical details
The vulnerability is a hard-coded credentials flaw in the /etc/config/easycwmp file of LB-LINK X-PRO version 1.0.22-20231206. The easycwmp TR-069 component stores fixed, unchangeable credentials that are accessible to network-based attackers. An attacker can exploit this remotely by connecting to the management interface and authenticating with the hard-coded credentials, gaining full or partial administrative control of the device. The exploit code has been publicly released, and the vendor did not respond to early disclosure attempts. Patching status is unknown.
Affected products
- LB-LINK X-PRO 1.0.22-20231206
Timeline
- 2026-08-15: disclosed
- exploited: public exploit released