Executive brief
LB-Link WR1210M is a wireless router used to provide network connectivity in homes and small businesses. The backup utility, accessible via a web interface, fails to authenticate users before allowing critical configuration operations. An attacker with local network access can export or modify the router's configuration without credentials, potentially compromising network security and enabling further attacks.
Technical details
This is an authentication bypass vulnerability in the Backup Endpoint component, specifically in the /www/cgi-bin/backup.cgi script's main function. The flaw allows unauthenticated access to backup and restore operations on the router. Attack precondition: attacker must be on the same local network as the affected device (adjacent network vector). Successful exploitation enables an attacker to dump the router configuration (which may contain credentials) or inject a malicious configuration to modify network settings, create backdoors, or redirect traffic. The vendor did not respond to early disclosure attempts. No patch status is currently known.
Affected products
- LB-Link WR1210M 1.0.3
Timeline
- 2026-08-17: disclosed
- other: Vendor contacted early but did not respond