Impact
A command injection flaw in the bs_SetLimitCli_info function of the libshare.so library on the LB-Link Router AC2100_AZ3 V1.0.4 allows an attacker to embed shell metacharacters or payloads into a user‑supplied parameter. The input is not validated before being passed to a system command context, enabling execution of arbitrary OS commands. This can compromise confidentiality, integrity, and availability of the device and any connected networks.
Affected Systems
The vulnerability affects the LB-Link Router AC2100_AZ3 model running firmware version 1.0.4. No other vendors or product variants are identified.
Risk and Exploitability
The lack of input sanitization makes the vulnerability easily exploitable, likely via remote configuration interfaces. Attackers could achieve full remote command execution if they can reach the router. Since no known exploit exists yet and the risk data is unavailable, the probability remains uncertain, but the potential impact is high due to the nature of command injection. The router is not listed in the CISA KEV catalog, and no EPSS score is available.
OpenCVE Enrichment