ZeroHour

CVE-2026-35869

Unauthenticated Command Injection in LB-Link AC450M Router Firmware

CVSS 3.1
9.8 critical
EPSS
1%p70
Published
()
Modified
AI analysis

LB-Link's AC450M router running firmware V4.0.0 contains a critical command injection flaw in the bs_SetLimitCli_info function of its libshare.so library, where user-supplied input is passed into a system-level command execution context without adequate validation or sanitization. A remote, unauthenticated attacker can trigger the flaw by injecting shell metacharacters or crafted payloads into the vulnerable parameter. Successful exploitation yields execution of arbitrary operating system commands on the router, consistent with the critical (9.8) CVSS score covering confidentiality, integrity, and availability. Any unit deployed on firmware V4.0.0, especially one whose management interface is reachable from the network, is affected. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported, and EPSS currently assigns a 1.3% probability of exploitation within the next 30 days.

What to do: Limit the router's management interface to trusted LAN segments and avoid exposing it directly to the internet, since the flaw is remotely exploitable without credentials. Identify deployed AC450M units and check whether they run firmware V4.0.0, then watch LB-Link's support channels for a corrected firmware release, as no fixed version is documented yet. Until a patch is available, firewalling WAN-side access to the web management UI is the primary mitigation.

Affected
LB-Link AC450M router (libshare.so, bs_SetLimitCli_info)V4.0.0
Estimated exposure
unknown; plausibly thousands to tens of thousands of consumer/SOHO units — No public install-base counts or internet-scan data exist for this single-model budget-brand router, so the estimate rests only on LB-Link's small consumer market share and typical home/SOHO deployment patterns.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.