Executive brief
The LB-Link AC2100_AZ3 is a wireless router used to provide network connectivity in homes and small businesses. A flaw in the router's web interface allows an attacker to inject arbitrary shell commands by manipulating network parameters, leading to complete takeover of the device and potential compromise of all connected network traffic.
Technical details
A command injection vulnerability exists in the bs_SetLimitCli_info function within libshare.so, where user-supplied MAC address parameters are unsafely concatenated into OS-level commands without proper sanitization or validation. The vulnerable code path begins in the goahead web server, which extracts user-controllable parameters (mac, time1, time2) via websGetVar and passes them to bs_SetLimitCli_info, which then directly concatenates the mac parameter into a system command via the bl_do_system function. An unauthenticated network attacker can inject shell metacharacters (pipes, command separators, backticks) into the mac parameter to achieve arbitrary command execution with router privileges. The vulnerability is network-reachable and requires no authentication or user interaction. A patch or firmware update from LB-Link has not been confirmed as available.
Affected products
- LB-Link AC2100_AZ3 V1.0.4
Timeline
- 2026-08-27: disclosed: CVE-2026-35868 published on NVD