Impact
A command injection flaw exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-Link Router AC450M. The vulnerability stems from insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context, allowing an attacker to inject shell metacharacters or payloads that are executed as arbitrary operating system commands. This weakness can lead to full compromise of the device, exposing its configuration, network interfaces, and potentially enabling lateral movement within the network.
Affected Systems
The affected product is the LB-Link Router AC450M running firmware version V4.0.0. No other vendors or versions are listed, so the impact is limited to this specific router model and firmware build.
Risk and Exploitability
While the CVSS score is not provided and EPSS data are unavailable, the nature of the flaw—arbitrary command execution—implies a high severity risk. The vulnerability is listed as not in the CISA KEV catalog, suggesting no publicly known exploits at the time of this analysis. The attack vector is inferred to involve any entity capable of supplying input to the vulnerable function, which may be possible through configuration interfaces or remote management protocols. Given the potential for remote compromise, this vulnerability carries a significant risk for affected systems.
OpenCVE Enrichment