PT-2026-53682 · Openwrt · Luci-App-Tailscale-Community
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
luci-app-tailscale-community (affected versions not specified)
Description
An issue in the
tailscale.do login RPC method allows authenticated users to execute arbitrary commands with root privileges. This occurs because the loginserver and loginserver authkey parameters are improperly quoted within a double-quoted shell command, enabling shell substitutions such as $() to be evaluated by the outer shell before argument processing.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luci-App-Tailscale-Community