CVE-2025-7564 | LB-LINK BL-AC3600 1.0.22 /etc/shadow hard-coded credentials (EUVD-2025-21303)
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials.
This vulnerability is handled as CVE-2025-7564. Local access is required to approach this attack. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.