CVE-2026-35867: Command Injection
Published Sep 13, 2026
·Updated
A Command Injection vulnerability exists in the bsSetLimitCliinfo function within the libshare.so library of the LB-LINK router AC1900AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/setLimitClientcfg" call but does not already have administrative access to the device.
Affected Software
1 affected component
LB-LINK LB-LINK router AC1900_AZ2=V1.0.2
Event History
Sep 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require prior administrative access?
No. The vulnerability is described as exploitable by an actor who can make a POST request to /goform/set_LimitClient_cfg without already having administrative access to the device.