Impact
A command injection flaw exists in the bs_SetLimitCli_info function of the libshare.so library on the LB-Link Router AC2100_AZ3 V1.0.4. The function fails to validate or sanitize user‑supplied input before passing it to a system command, allowing an attacker to embed shell metacharacters or payloads and execute arbitrary operating‑system commands. This can compromise the confidentiality, integrity, and availability of the device and any connected networks.
Affected Systems
The vulnerability affects the LB-Link Router AC2100_AZ3 model running firmware version 1.0.4; no other vendors or product variants are identified.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is a remote configuration or management interface that accepts user input for bs_SetLimitCli_info. The lack of input sanitization makes the flaw easily exploitable, granting full remote command execution if the router is reachable. The CVSS score of 9.8 indicates critical severity, while an EPSS score of < 1% signals a low exploitation probability. The router is not listed in the CISA KEV catalog, but the high impact warrants urgent attention.
OpenCVE Enrichment