CVE Feed

    Dashboard / CVE / CVE-2025-57278

    CVE-2025-57278

    The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or verifying client identity. There are no session tokens, cookies, or unique identifiers in place. This flaw allows an attacker to obtain full administrative access simply by configuring their device to use the same IP address as a previously authenticated user. This results in a complete authentication bypass.

    Published:Sep 9, 2025
    Last Modified:Oct 10, 2025
    EPS:Sep 9, 2025
    EPSS Score:0.00048
    CVSS Score:8.8

    Affected Products

    Vendor
    Lb-link
    Product
    Bl-cpe300m
    Vendor
    Lb-link
    Product
    Bl-cpe300m Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High