External risk intelligence

LB-link Router AC2100 Command Injection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-35868

This vulnerability affects a wireless router, which is a network device commonly deployed at the edge of a network. As a gateway/router product, its management interfaces or configuration parameters are often exposed to the network, making it a likely target for internet-reachable exploitation in common residential or small business deployments.

Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A command injection vulnerability has been identified in a specific function within the libshare.so library of the LB-link Router AC2100. This flaw allows unauthenticated attackers to execute arbitrary operating system commands remotely, potentially leading to a complete compromise of the affected device.

  • Unauthenticated remote command execution is possible.
  • Routers are critical network access points.
  • Confirm relevance and exposure of this router.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to a network-exposed management interface of the router. This request would target the `bs_SetLimitCli_info` function, which is susceptible to command injection due to a lack of proper input validation. If successful, the attacker could execute arbitrary commands on the router's operating system.

  • No special access needed.
  • Inject commands into network request.
  • Execute arbitrary commands on device.

Live Threat

Current exploitation, exposure, and threat context

A command injection vulnerability in the libshare.so library of LB-link Router AC2100 could allow an attacker to execute arbitrary operating system commands. This is possible when an attacker sends specially crafted input with shell metacharacters to the vulnerable function, provided the router's management interface is accessible.

  • System commands and router configuration.
  • Injecting malicious commands through network access.
  • Unauthorized control of the router's operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical command injection vulnerability in LB-link Router AC2100_AZ3 impacts network edge devices, likely managed by infrastructure or platform teams. The first step is to locate all instances of this router, assess their network exposure and business criticality, and identify the accountable owner before planning remediation.

  • Own by Infrastructure/Platform teams.
  • Verify network exposure and business criticality.
  • Plan phased remediation by risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the LB-link Router AC2100_AZ3?

The LB-link Router AC2100_AZ3 is a networking device designed to manage internet traffic and provide wireless connectivity for homes or small businesses. It functions as a gateway, serving as the bridge between your local devices and the external internet. The software component libshare.so manages various internal operations for the router, including handling certain system-level configuration tasks.

What does command injection mean for CVE-2026-35868?

This vulnerability, classified as CWE-20 (Improper Input Validation), occurs when the router's software blindly trusts data provided by a user. Instead of checking if the input is safe, the system accidentally processes that input as an operating system command. By injecting specific characters, an attacker can trick the router into running unauthorized code, effectively giving them control over the device's operating system.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted request to the router's management interface that targets the vulnerable bs_SetLimitCli_info function. The bug only activates if the input contains malicious shell metacharacters; standard, properly formatted requests for router settings do not trigger the flaw. Authentication is not required to initiate this attack.

Is my router at risk?

Halo Surface Signal indicates this device is a likely target because routers sit at the edge of a network, often with management interfaces accessible from the internet. If your specific router is reachable from outside your local network, your risk is significantly higher. You should prioritize checking if the administrative interface is exposed to the public internet versus restricted to local access only.

What should I do if I use this router?

Your first step is to create an inventory of all instances of the AC2100_AZ3 in your environment. Determine which units have management interfaces exposed to the internet and assess the business impact if these devices were compromised. Once you have identified these high-risk assets, work with your infrastructure or platform team to limit network access to the management console until a formal remediation path is established.

References