Description
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw in the bs_SetLimitCli_info function of the libshare.so library on the LB-Link Router AC2100_AZ3 V1.0.4 allows an attacker to embed shell metacharacters or payloads into a user‑supplied parameter. The input is not validated before being passed to a system command context, enabling execution of arbitrary OS commands. This can compromise confidentiality, integrity, and availability of the device and any connected networks.

Affected Systems

The vulnerability affects the LB-Link Router AC2100_AZ3 model running firmware version 1.0.4. No other vendors or product variants are identified.

Risk and Exploitability

The lack of input sanitization makes the vulnerability easily exploitable, likely via remote configuration interfaces. Attackers could achieve full remote command execution if they can reach the router. Since no known exploit exists yet and the risk data is unavailable, the probability remains uncertain, but the potential impact is high due to the nature of command injection. The router is not listed in the CISA KEV catalog, and no EPSS score is available.

Generated by OpenCVE AI on August 28, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to a firmware version that contains the bs_SetLimitCli_info patch or a newer release that eliminates the command injection.
  • If a firmware upgrade is not available, restrict management access to the router to trusted internal networks and block external network exposure to limit attacker reach.
  • If a firmware upgrade is not available, disable or block the router’s remote management interface that invokes bs_SetLimitCli_info to restrict exposure.

Generated by OpenCVE AI on August 28, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Command Injection in bs_SetLimitCli_info Function of LB-Link Router AC2100_AZ3 V1.0.4
Weaknesses CWE-77

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T17:05:30.577Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-35868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:40.463

Modified: 2026-08-27T20:17:40.463

Link: CVE-2026-35868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:30:07Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')