Executive brief
LB-Link BL-CPE600EU is a network access point device. A flaw in its Configuration Backup Handler allows remote attackers to extract sensitive information from the device's configuration, potentially exposing network credentials and settings. The vendor has not responded to disclosure notifications.
Technical details
An information disclosure vulnerability exists in the Mifi_config.bin file handled by the Configuration Backup Handler component. The flaw allows remote attacks without authentication to retrieve sensitive configuration data. A public exploit is available, though no active exploitation in the wild has been confirmed.
Affected products
- LB-Link BL-CPE600EU 5.8.13
Timeline
- 2026-09-23: disclosed
- other: Public exploit released; vendor non-responsive