PT-2026-55199 · Unknown · Travelmate+1
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
luci-app-travelmate versions 2.4.5-r3 through 2.4.6-1
travelmate versions 2.4.5-r3 through 2.4.6-1
Description
A privilege-escalation flaw exists where a LuCI/rpcd session with write ACL for luci-app-travelmate is granted config-wide UCI write access to the travelmate configuration. Although the user interface restricts the auto-login script selection to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service, which runs as root, reads the raw UCI
script and script args values and executes the path when the captive-portal auto-login branch f check() in travelmate-functions.sh is reached. An attacker with delegated write permissions can change script to /bin/sh and provide controlled arguments in script args to execute arbitrary commands as root.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luci-App-Travelmate
Travelmate