ZeroHour

CVE-2026-35868

Unauthenticated Command Injection in LB-Link AC2100_AZ3 Router (CVE-2026-35868)

CVSS 3.1
9.8 critical
EPSS
1%p70
Published
()
Modified
AI analysis

CVE-2026-35868 is a command injection flaw in the bs_SetLimitCli_info function of the libshare.so library in the LB-Link AC2100_AZ3 router running firmware V1.0.4. User-supplied input is passed to a system-level command execution context without adequate validation or sanitization, allowing an attacker to inject shell metacharacters or crafted payloads into the vulnerable parameter. Because the flaw is reachable over the network without credentials or user interaction (CVSS 9.8, AV:N/PR:N/UI:N), a remote unauthenticated attacker can execute arbitrary operating system commands on the router, potentially gaining full device control, altering configuration, or pivoting to connected networks. Only users of the LB-Link AC2100_AZ3 router (firmware V1.0.4 is the version identified in available data) are affected. Exploitation has not been observed in the wild, no public proof-of-concept is known, and the flaw is not in CISA's KEV, though its EPSS score of 1.4% (70th percentile) suggests a moderate chance of exploitation within 30 days.

What to do: Check whether your router is an LB-Link AC2100_AZ3 running firmware V1.0.4 and apply the vendor's patched firmware as soon as it is released. Until patched, do not expose the router's web management interface to the internet (disable remote/WAN management, restrict administration to the LAN or VPN), and monitor the device for unexpected processes or configuration changes that could indicate command injection attempts.

Affected
LB-link AC2100_AZ3 router (libshare.so, bs_SetLimitCli_info function)V1.0.4
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.