A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in bs_SetLimitCli_info Allows Remote Command Execution on LB-Link Router AC450M |
Mon, 31 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in LB-Link Router AC450M bs_SetLimitCli_info | |
| Weaknesses | CWE-78 |
Mon, 31 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in LB-Link Router AC450M bs_SetLimitCli_info | |
| Weaknesses | CWE-78 |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-27T00:00:00.000Z
Updated: 2026-08-31T20:49:41.860Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35869
No data.
Status : Deferred
Published: 2026-08-27T20:17:40.620
Modified: 2026-09-08T19:29:09.680
Link: CVE-2026-35869
No data.