Junglewise Threat Intelligence

CVE-2026-35869: LB-Link AC450M command injection in libshare.so

CVE-2026-35869 · Severity: critical · CVSS 9.8 · Published 2026-08-27

Vendors: LB-Link.

Executive brief

The LB-Link AC450M router contains a command injection flaw in its web-based administration interface. An attacker can inject arbitrary shell commands through the device's configuration functions, potentially gaining complete control of the router and any networks it protects. This could lead to data theft, network compromise, or service disruption.

Technical details

A command injection vulnerability exists in the bs_SetLimitCli_info function within libshare.so, triggered via the /goform/set_LimitClient_cfg endpoint in the GoAhead web server. The vulnerability stems from insufficient validation and sanitization of user-supplied input (mac, time1, time2 parameters) before OS command execution. An attacker can inject shell metacharacters or payloads through these parameters to execute arbitrary OS commands with router privileges. No authentication bypass is required beyond access to the web interface; this can be exploited remotely if the administration interface is exposed, or locally from the network. Patches or mitigations have not been confirmed as available at the time of this advisory.

Affected products

  • LB-Link AC450M V4.0.0

Timeline

  • 2026-08-27: disclosed: Vulnerability disclosed via GitHub and NVD

References