CVE-2026-35867
3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
Summary
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| LB-LINK | AC1900 firmware | 1.0.2 | affected |
Weaknesses
- CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.