---
id: CVE-2026-19900
title: A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206
summary: >-
  A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted
  element is an unknown function of the file /etc/shadow. The manipulation leads
  to hard-coded credentials. It is possible to initiate the attack remotely. A
  hig…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-259
  - CWE-798
published: '2026-08-15'
updated: '2026-08-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19900'
references:
  - url: >-
      https://github.com/DavCloudz/cve/blob/main/B-Link/B-Link%20AC1200%20X-PRO(AC6)%20Hardcoded%20Credentials%20Vulnerability.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-19900'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/870712'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/390090'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/390090/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - exploit-available
ingestedAt: '2026-08-16T13:39:03.403Z'
epss: 0.02941
epssPercentile: 0.86572
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/on3sk-0x1/cve-2026-19900-PoC'
  nuclei:
    - CVE-2026-19900
  checkedAt: '2026-09-26T09:05:39.683Z'
exploitAvailable: true
---

## Overview

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
