---
id: CVE-2026-35867
title: >-
  A Command Injection vulnerability exists in the bs_SetLimitCli_info function
  within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via
  shell metacharacters, if the device is deployed in a scenario where an actor
  is able …
summary: >-
  A Command Injection vulnerability exists in the bs_SetLimitCli_info function
  within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via
  shell metacharacters, if the device is deployed in a scenario where an actor
  is able …
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-78
vendor: LB-LINK
product: AC1900 firmware
affected:
  - ac1900_firmware 1.0.2
published: '2026-09-13'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35867'
references:
  - url: >-
      https://github.com/Orcust-Automaton/Vulnerability/blob/main/LB-Link/AC1900_AZ2/bs_SetLimitCli_info.md
    label: cve@mitre.org
  - url: >-
      https://github.com/Orcust-Automaton/Vulnerability/blob/main/LB-Link/AC1900_AZ2/bs_SetLimitCli_info.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.0052
epssPercentile: 0.43208
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T15:51:27.526500Z'
ingestedAt: '2026-09-14T15:23:07.468Z'
---

## Overview

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
