PT-2026-90976 · Lb Link · Ac1900 Firmware
CVE-2026-35867
·
Published
2026-09-13
·
Updated
2026-09-14
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
LB-LINK AC1900 AZ2 version 1.0.2
Description
Command injection is possible through the use of shell metacharacters in the
bs SetLimitCli info() function located in the libshare.so library. This occurs when an actor makes a "POST /goform/set LimitClient cfg" call to a device where they do not have administrative access.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ac1900 Firmware