AC1900 firmware vulnerability

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a "POST /goform/set_LimitClient_cfg" call but does not already have administrative access to the device.

Published 13 Sep 2026Updated 13 Sep 20261 sources
CVSS 3.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.