CVE-2026-35867
- EPSS 0.52%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "PO...
CVE-2025-1609
- EPSS 9.98%
- Veröffentlicht 24.02.2025 02:15:32
- Zuletzt bearbeitet 04.11.2025 21:02:30
A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this vulnerability is the function websGetVar of the file /goform/set_cmd. The manipulation of the argument cmd leads to os command injection. The a...
CVE-2025-1610
- EPSS 12.94%
- Veröffentlicht 24.02.2025 02:15:32
- Zuletzt bearbeitet 04.11.2025 21:05:20
A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of the file /goform/set_blacklist. The manipulation of the argument mac/enable leads to os command injection. The a...
CVE-2025-1608
- EPSS 9.98%
- Veröffentlicht 24.02.2025 01:15:10
- Zuletzt bearbeitet 04.11.2025 20:59:14
A vulnerability, which was classified as critical, was found in LB-LINK AC1900 Router 1.0.2. Affected is the function websGetVar of the file /goform/set_manpwd. The manipulation of the argument routepwd leads to os command injection. It is possible ...