PT-2026-53683 · Unknown · Luci-Proto-Openvpn
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
luci-proto-openvpn versions prior to 0.11.1
Description
An authenticated LuCI user with OpenVPN protocol configuration access can execute arbitrary commands as root. This occurs because the
generateKey ubus method interpolates the cl meta parameter into a shell command without proper escaping or quoting, allowing the injection of shell metacharacters via the popen() function.Recommendations
Update luci-proto-openvpn to the version containing commit e4ff45e.
Restrict access to the
cl meta parameter in the generateKey method to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luci-Proto-Openvpn