CVE Watchtower

← Back to CVE List

CVE-2026-35867NVD

Description

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device.
Severity Level
LOW (3.1)
Published Date
13/09/2026
Last Modified
13/09/2026
Exploitation Status
????
EPSS Score
0.52% (percentile 43.2%)

CVSS Base Metrics

CVSS v3 (3.1)
LOW 3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L

Weaknesses (CWE)

📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.