CVE-2026-35868
LB-Link · Router AC2100_AZ3
A command injection vulnerability in the LB-Link Router AC2100_AZ3 allows unauthenticated remote attackers to execute arbitrary system commands via the bs_SetLimitCli_info function.
Executive summary
This critical command injection vulnerability in the LB-Link Router AC2100_AZ3 poses an extreme risk of full system compromise by unauthenticated remote attackers.
Vulnerability
This flaw exists in the libshare.so library within the bs_SetLimitCli_info function. It occurs because the software fails to sanitize user-supplied input, allowing an unauthenticated remote attacker to inject malicious shell commands.
Business impact
The CVSS score of 9.8 reflects the high severity of this flaw, as it allows for complete system takeover without requiring authentication. Successful exploitation can lead to total loss of confidentiality, integrity, and availability, potentially allowing attackers to pivot into internal networks, intercept sensitive traffic, or use the device as a persistent beachhead for further malicious activities.
Remediation
Immediate Action: Since a specific patch is not currently identified, isolate the affected router from external network access immediately to prevent remote exploitation.
Proactive Monitoring: Review system and firewall logs for unusual outbound traffic or unexpected command execution patterns originating from the device management interface.
Compensating Controls: Implement strict network access control lists (ACLs) to restrict access to the device management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists (attributed to the researcher's technical write-up linked in the CVE record).
Analyst recommendation
Given the critical severity and the existence of a public proof-of-concept, users must treat this vulnerability with the highest level of urgency. Until a vendor-supplied firmware update is available, the device should be removed from internet-facing configurations to eliminate the primary attack vector.