The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or verifying client identity. There are no session tokens, cookies, or unique identifiers in place. This flaw allows an attacker to obtain full administrative access simply by configuring their device to use the same IP address as a previously authenticated user. This results in a complete authentication bypass.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lb-link
Lb-link bl-cpe300m Lb-link bl-cpe300m Firmware |
|
CPEs | cpe:2.3:h:lb-link:bl-cpe300m:-:*:*:*:*:*:*:* cpe:2.3:o:lb-link:bl-cpe300m_firmware:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Lb-link
Lb-link bl-cpe300m Lb-link bl-cpe300m Firmware |
Mon, 22 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 | |
Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or verifying client identity. There are no session tokens, cookies, or unique identifiers in place. This flaw allows an attacker to obtain full administrative access simply by configuring their device to use the same IP address as a previously authenticated user. This results in a complete authentication bypass. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-09-09T00:00:00.000Z
Updated: 2025-09-22T15:36:12.206Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57278

Updated: 2025-09-22T15:36:07.914Z

Status : Analyzed
Published: 2025-09-09T19:15:57.607
Modified: 2025-10-10T17:56:10.140
Link: CVE-2025-57278

No data.