PT-2026-90976 · Lb Link · Ac1900 Firmware

CVE-2026-35867

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions LB-LINK AC1900 AZ2 version 1.0.2
Description Command injection is possible through the use of shell metacharacters in the bs SetLimitCli info() function located in the libshare.so library. This occurs when an actor makes a "POST /goform/set LimitClient cfg" call to a device where they do not have administrative access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35867

Affected Products

Ac1900 Firmware