A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 17 Jul 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Lb-link
Lb-link bl-ac3600
Lb-link bl-ac3600 Firmware
CPEs cpe:2.3:h:lb-link:bl-ac3600:-:*:*:*:*:*:*:*
cpe:2.3:o:lb-link:bl-ac3600_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lb-link
Lb-link bl-ac3600
Lb-link bl-ac3600 Firmware

Mon, 14 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0001}


Mon, 14 Jul 2025 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title LB-LINK BL-AC3600 shadow hard-coded credentials
Weaknesses CWE-259
CWE-798
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-07-14T02:32:05.381Z

Updated: 2025-07-14T14:47:58.385Z

Reserved: 2025-07-12T21:11:53.262Z

Link: CVE-2025-7564

cve-icon Vulnrichment

Updated: 2025-07-14T14:47:46.887Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-14T03:15:24.557

Modified: 2025-07-17T17:46:52.167

Link: CVE-2025-7564

cve-icon Redhat

No data.