PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35869 LB-link CVE debrief

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands. The CVE record was published on 2026-08-27T20:17:40.620Z and has not been modified since then. Limited information available; further verification recommended. Additional evidence review and defensive verification tasks are necessary to understand the full scope of this vulnerability. Administrators and security teams should prioritize verification and remediation of this critical vulnerability. This includes reviewing system configurations, applying vendor remediation, and monitoring for suspicious activity.

Vendor
LB-link
Product
Router AC450M
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-08-31
Advisory published
2026-08-27
Advisory updated
2026-08-31

Who should care

Administrators and security teams responsible for LB-link Router AC450M V4.0.0 systems should prioritize verification and remediation of this critical vulnerability. This includes reviewing system configurations, applying vendor remediation, and monitoring for suspicious activity. Additionally, operators and platform administrators should assess their exposure and implement compensating controls if necessary.

Technical summary

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. Insufficient validation and sanitization of user-supplied input allow for command injection, enabling attackers to execute arbitrary operating system commands. This vulnerability has a high CVSS score of 9.8, indicating critical severity. The affected product and its components should be reviewed for exposure.

Defensive priority

Critical vulnerability in LB-link Router AC450M V4.0.0 requires immediate attention due to high CVSS score of 9.8.

Recommended defensive actions

  • Verify and apply vendor remediation for LB-link Router AC450M V4.0.0
  • Conduct inventory checks for affected systems
  • Implement compensating controls and monitor for suspicious activity
  • Restrict access to vulnerable systems and parameters
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. Insufficient validation and sanitization of user-supplied input allow for command injection. Limited information available; further verification recommended. Additional evidence review and defensive verification tasks are necessary to understand the full scope of this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35869 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35869

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35869 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35869

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.