SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19971

MEDIUM · CVSS 4.7 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A vulnerability in the LB-Link WR1210M 1.0.3 affects the Backup Endpoint functionality, specifically in the backup.cgi file, leading to missing authentication. This flaw allows unauthorized access to backup features, but it can only be exploited from within the local network. Network administrators managing this device should prioritize addressing this issue to mitigate potential unauthorized access risks.

CVE
CVE-2026-19971
Severity
MEDIUM
CVSS
4.7
EPSS
0.28%

Original NVD Description

A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the local network. The vendor was contacted early about this disclosure but did not respond in any way.