A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device. | |
| First Time appeared |
Lb-link
Lb-link ac1900 Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:lb-link:ac1900_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lb-link
Lb-link ac1900 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-13T21:34:39.177Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35867
No data.
Status : Received
Published: 2026-09-13T22:16:59.473
Modified: 2026-09-13T22:16:59.473
Link: CVE-2026-35867
No data.
OpenCVE Enrichment
No data.
Weaknesses