CVE-2026-35869
Unauthenticated Command Injection in LB-Link AC450M Router Firmware
LB-Link's AC450M router running firmware V4.0.0 contains a critical command injection flaw in the bs_SetLimitCli_info function of its libshare.so library, where user-supplied input is passed into a system-level command execution context without adequate validation or sanitization. A remote, unauthenticated attacker can trigger the flaw by injecting shell metacharacters or crafted payloads into the vulnerable parameter. Successful exploitation yields execution of arbitrary operating system commands on the router, consistent with the critical (9.8) CVSS score covering confidentiality, integrity, and availability. Any unit deployed on firmware V4.0.0, especially one whose management interface is reachable from the network, is affected. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported, and EPSS currently assigns a 1.3% probability of exploitation within the next 30 days.
What to do: Limit the router's management interface to trusted LAN segments and avoid exposing it directly to the internet, since the flaw is remotely exploitable without credentials. Identify deployed AC450M units and check whether they run firmware V4.0.0, then watch LB-Link's support channels for a corrected firmware release, as no fixed version is documented yet. Until a patch is available, firewalling WAN-side access to the web management UI is the primary mitigation.
| LB-Link AC450M router (libshare.so, bs_SetLimitCli_info) | V4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.