Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Faller-Dql

#14317of 56,326
19.8Total CVSS
Vulnerabilities · 2
Critical
2
PT-2026-71904
9.9
2026-08-13
Openwrt · Luci-App-Openvpn · CVE-2026-72841
**Name of the Vulnerable Software and Affected Versions** luci-app-openvpn (affected versions not specified) **Description** Authenticated users can perform path traversal and write arbitrary files outside the intended directory because the software fails to properly validate the `instance name2` parameter during file upload. This allows attackers to upload malicious payloads, such as SSH keys, into system directories to achieve persistent root code execution upon reboot. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-71905
9.9
2026-08-13
Openwrt · Luci-App-Lxc · CVE-2026-72842
**Name of the Vulnerable Software and Affected Versions** luci-app-lxc (affected versions not specified) **Description** An ACL inconsistency allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. By using path traversal via `/.%2E` in the `lxc name` parameter, an attacker can escape container directories and control host-side scripts executed through `lxc.hook.start-host`, resulting in root code execution on the OpenWrt host. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.