CVE-2026-19900 is a hard-coded credentials vulnerability affecting LB-LINK X-PRO version 1.0.22-20231206. The issue is described as involving an unknown function associated with the system password storage component represented by /etc/shadow, resulting in the presence or use of embedded credentials within the affected product. The vulnerability can be exploited remotely and does not require prior authentication or user interaction, although exploitation is assessed as high complexity. Public exploit information is reported to be available. The weakness is most appropriately classified as CWE-798, and it has also been associated with CWE-259 due to the hard-coded password aspect.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file repository contains a README and a standalone Go proof-of-concept for CVE-2026-19900 affecting the LB-LINK X-PRO/AC1200 X-PRO (AC6) management interface. The executable parses a target URL, always constructs the target endpoint as <scheme>://<host>/goform/set_cmd, then POSTs a URL-encoded cmd parameter while setting the Cookie header to user=(null). It is an active exploitation tool rather than a detection-only script: it accepts arbitrary one-shot commands with -c or provides an interactive command loop with -i. Responses are parsed as JSON for the cmdinfo field, with raw response output used as a fallback. No external exploitation framework, callback infrastructure, hardcoded victim host, or embedded secondary payload is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A hard-coded credentials vulnerability affecting LB-LINK X-PRO 1.0.22-20231206, involving an unknown function related to /etc/shadow and allowing remote attack.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.