3.1
CVE-2026-35867
- EPSS 0.52%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
- Erkennungen
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLB-LINK
≫
Produkt
AC1900 firmware
Default Statusunknown
Version
1.0.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.427 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 3.1 | 0.5 | 2.5 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://github.com/Orcust-Automaton/Vulnerability/blob/main/LB-Link/AC1900_AZ2/bs_SetLimitCli_info.md