CVE-2026-19901Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-15); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-15: 3Mentions · 2026-08-16: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 108-1508-16
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-153
Disclosure3
2026-08-161
Disclosure1
Full discourse4 posts
  • ADK Cyber@ADKCyber
    Disclosure

    High CVSS 8.2 flaw (CVE-2026-19901) in LB-LINK X-PRO 1.0.22 leaves hard-coded credentials in easycwmp config. Review affected devices in your environment. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/SUqIo9OL0l

    Post summary

    The tweet announces CVE-2026-19901, a high‑CVSS 8.2 vulnerability in LB‑LINK X‑PRO 1.0.22 that exposes hard‑coded credentials in the easycwmp config, but it provides no PoC, exploit, or patch details.

    0000051
    93 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19901 Hard-Coded Credentials in LB-LINK X-PRO 1.0.22-20231206 via /etc/config/easycwmp https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19901

    Post summary

    The entry announces the discovery of CVE-2026-19901, describing hard‑coded credentials in LB‑LINK X‑PRO via /etc/config/easycwmp, with no evidence of exploitation, PoC, patch, or false‑positive claims.

    00000122
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19901 A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in h… https://www.cve.org/CVERecord?id=CVE-2026-19901 ----- Traducción: CVE-2026-19901 Se … https://infoflow.cloud`

    Post summary

    A new vulnerability CVE‑2026‑19901 in LB‑LINK X‑PRO has been announced, impacting an unknown function of /etc/config/easycwmp, with no sign of active exploitation, patches, or PoC available.

    0000028
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19901 A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in h… https://www.cve.org/CVERecord?id=CVE-2026-19901

    Post summary

    A new vulnerability, CVE-2026-19901, was disclosed for LB-LINK X-PRO 1.0.22-20231206, noting an issue with an unknown function in /etc/config/easycwmp, but no further technical details, PoC, or patch information are provided.

    000001.1K
    57.9K followersView on X

Explore more