Description
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
Published: 2026-08-27
Score: 9.8 Critical
EPSS: 1.4% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw exists in the bs_SetLimitCli_info function of the libshare.so library on the LB-Link Router AC2100_AZ3 V1.0.4. The function fails to validate or sanitize user‑supplied input before passing it to a system command, allowing an attacker to embed shell metacharacters or payloads and execute arbitrary operating‑system commands. This can compromise the confidentiality, integrity, and availability of the device and any connected networks.

Affected Systems

The vulnerability affects the LB-Link Router AC2100_AZ3 model running firmware version 1.0.4; no other vendors or product variants are identified.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is a remote configuration or management interface that accepts user input for bs_SetLimitCli_info. The lack of input sanitization makes the flaw easily exploitable, granting full remote command execution if the router is reachable. The CVSS score of 9.8 indicates critical severity, while an EPSS score of < 1% signals a low exploitation probability. The router is not listed in the CISA KEV catalog, but the high impact warrants urgent attention.

Generated by OpenCVE AI on September 1, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that contains the bs_SetLimitCli_info patch or a newer release that eliminates the command injection.
  • If an upgrade is not available, restrict management access to the router to trusted internal networks and block external exposure to limit attacker reach.
  • If an upgrade is not available, disable or block the router’s remote management interface that invokes bs_SetLimitCli_info to reduce exposure.

Generated by OpenCVE AI on September 1, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in LB-Link Router AC2100_AZ3 bs_SetLimitCli_info

Mon, 31 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection in bs_SetLimitCli_info Function of LB-Link Router AC2100_AZ3 V1.0.4
Weaknesses CWE-77

Mon, 31 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 28 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Command Injection in bs_SetLimitCli_info Function of LB-Link Router AC2100_AZ3 V1.0.4
Weaknesses CWE-77

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T20:48:33.096Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-35868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-27T20:17:40.463

Modified: 2026-09-08T19:29:09.680

Link: CVE-2026-35868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T00:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation