Impact
A command injection flaw exists in the bs_SetLimitCli_info function of the libshare.so library in LB‑Link AC1900 firmware. The vulnerability allows an attacker request to /goform/set_LimitClient_cfg, resulting in execution of arbitrary shell commands. This flaw is rooted in improper input validation and is classified as CWE‑78. Based on the description, it is inferred that administrative privileges are not required to exploit this weakness; the attacker only needs the ability to reach the vulnerable API endpoint to cause remote code execution, potentially compromising device confidentiality, integrity, and availability.
Affected Systems
Affected platforms include the LB‑Link AC1900 router running firmware version 1.0.2. Because the vulnerability is tied to a specific API endpoint, devices exposed to a network where attackers can reach this endpoint are at risk. Based on the description, it is inferred that any deployment of the affected firmware on a network exposed to untrusted hosts poses a threat.
Risk and Exploitability
With a CVSS score of 3.1, and the EPSS score of < 1% indicates a very low likelihood of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is a remote API call over the network, inferred from the requirement that an actor can make a POST request to the exposed endpoint. Although the EPSS suggests limited exploitation data, the lack of administrative access requirements means that attackers could potentially exploit the flaw from any external network point that can reach the router. Therefore, timely action is recommended to mitigate the possibility of remote code execution.
OpenCVE Enrichment