Executive brief
A command injection vulnerability exists in the LB-LINK AC1900_AZ2 router's network management library that allows unauthenticated remote attackers to execute arbitrary commands on the device. The vulnerability is triggered through a web interface endpoint that processes client bandwidth limit configurations without proper input validation, potentially allowing an attacker to gain control of the router and access the network it protects.
Technical details
The vulnerability is a command injection flaw in the bs_SetLimitCli_info function within libshare.so, a core library of the LB-LINK AC1900_AZ2 router running firmware version V1.0.2. The vulnerable endpoint is "POST /goform/set_LimitClient_cfg", which fails to properly sanitize shell metacharacters in user-supplied input before passing it to system command execution. An unauthenticated network-adjacent attacker can exploit this by crafting a malicious POST request with shell command injection payloads to achieve remote code execution. No administrative credentials are required for exploitation, and patches availability is not mentioned.
Affected products
- LB-LINK AC1900_AZ2 V1.0.2
Timeline
- 2026-09-13: disclosed