CVE-2026-35869: Command Injection
A Command Injection vulnerability exists in the bsSetLimitCliinfo function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
Affected Software
Event History
Frequently Asked Questions
Which product version is identified as affected?
The reported affected product is the LB-link Router AC450M running firmware V4.0.0.
What must an attacker do to exploit this issue?
An attacker must supply crafted input to the vulnerable parameter handled by bs_SetLimitCli_info. The input uses shell metacharacters or other payloads that reach a system-level command execution context.
What is the impact of successful exploitation?
Successful exploitation can result in execution of arbitrary operating system commands on the affected router.