CVE-2026-35868
—Unauthenticated Command Injection in LB-Link AC2100_AZ3 Router (CVE-2026-35868)
CVE-2026-35868 is a command injection flaw in the bs_SetLimitCli_info function of the libshare.so library in the LB-Link AC2100_AZ3 router running firmware V1.0.4. User-supplied input is passed to a system-level command execution context without adequate validation or sanitization, allowing an attacker to inject shell metacharacters or crafted payloads into the vulnerable parameter. Because the flaw is reachable over the network without credentials or user interaction (CVSS 9.8, AV:N/PR:N/UI:N), a remote unauthenticated attacker can execute arbitrary operating system commands on the router, potentially gaining full device control, altering configuration, or pivoting to connected networks. Only users of the LB-Link AC2100_AZ3 router (firmware V1.0.4 is the version identified in available data) are affected. Exploitation has not been observed in the wild, no public proof-of-concept is known, and the flaw is not in CISA's KEV, though its EPSS score of 1.4% (70th percentile) suggests a moderate chance of exploitation within 30 days.
What to do: Check whether your router is an LB-Link AC2100_AZ3 running firmware V1.0.4 and apply the vendor's patched firmware as soon as it is released. Until patched, do not expose the router's web management interface to the internet (disable remote/WAN management, restrict administration to the LAN or VPN), and monitor the device for unexpected processes or configuration changes that could indicate command injection attempts.
| LB-link AC2100_AZ3 router (libshare.so, bs_SetLimitCli_info function) | V1.0.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.