Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device. | |
| First Time appeared |
Lb-link
Lb-link ac1900 Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:lb-link:ac1900_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lb-link
Lb-link ac1900 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-13T21:34:39.177Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35867
No data.
Status : Received
Published: 2026-09-13T22:16:59.473
Modified: 2026-09-13T22:16:59.473
Link: CVE-2026-35867
No data.
OpenCVE Enrichment
No data.