Command Injection Vulnerability in LB-LINK Router AC1900_AZ2
CVE-2026-35867

3.1LOW

Key Information:

Vendor

Lb-link

Vendor
CVE Published:
13 September 2026

What is CVE-2026-35867?

A command injection vulnerability has been identified in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK AC1900_AZ2 router. This vulnerability allows an attacker, without prior administrative access, to exploit the device by sending specially crafted POST requests to the endpoint '/goform/set_LimitClient_cfg'. The ability to inject shell metacharacters can lead to unauthorized command execution, compromising the security of the device.

Affected Version(s)

AC1900 firmware 1.0.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.