Junglewise Threat Intelligence

CVE-2026-96606: LB-Link BL-CPE600EU information disclosure in configuration backup

CVE-2026-96606 · Severity: medium · CVSS 5.3 · Published 2026-09-23

Vendors: LB-Link.

Executive brief

LB-Link BL-CPE600EU is a network access point device. A flaw in its Configuration Backup Handler allows remote attackers to extract sensitive information from the device's configuration, potentially exposing network credentials and settings. The vendor has not responded to disclosure notifications.

Technical details

An information disclosure vulnerability exists in the Mifi_config.bin file handled by the Configuration Backup Handler component. The flaw allows remote attacks without authentication to retrieve sensitive configuration data. A public exploit is available, though no active exploitation in the wild has been confirmed.

Affected products

  • LB-Link BL-CPE600EU 5.8.13

Timeline

  • 2026-09-23: disclosed
  • other: Public exploit released; vendor non-responsive

References