CVE-2026-30612
Deferred Deferred - Pending Action

Arbitrary Code Execution in Time4 Popcorn

Vulnerability report for CVE-2026-30612, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-09-01

Assigner: MITRE

Description

An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-09-01
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
time4popcorn time4popcorn to 6.2.1.18 (inc)
time4popcorn time4popcorn to 6.2.1.17 (inc)
time4popcorn time4popcorn to 3.5.0.173 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-30612 is a command injection vulnerability affecting the LB-LINK AC1900_AZ2 Router (firmware version V1.0.2). It allows remote attackers to execute arbitrary code by injecting malicious shell commands through the bs_SetLimitCli_info function in the libshare.so library. The flaw occurs due to insufficient input validation in the mac parameter, which is passed unsafely to system-level commands via the bl_do_system function.

Detection Guidance

This CVE does not provide specific detection commands for the Time4 Popcorn vulnerability. However, for similar command injection flaws, monitor network traffic for suspicious HTTP POST requests to /goform/set_LimitClient_cfg with unusual parameters like mac, time1, or time2. Check logs for unexpected system command executions or reverse shell connections.

Impact Analysis

An attacker could exploit this to gain full control of the affected router, enabling them to intercept network traffic, install malware, or launch further attacks on connected devices. The vulnerability is triggered via a crafted HTTP POST request to /goform/set_LimitClient_cfg, allowing remote code execution without authentication.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is specific to a command injection flaw in a router firmware (LB-LINK AC1900_AZ2) rather than a data processing or storage system. However, if exploited, it could lead to unauthorized access to network resources, potentially compromising sensitive data and violating security policies.

Mitigation Strategies

Immediately update the firmware of the LB-LINK AC1900_AZ2 Router to the latest version to patch the vulnerability. Disable remote access to the router's web interface if not required. Monitor network traffic for unusual activity or unauthorized commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-30612. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart