PT-2026-57886 · Unknown · Luci-App-Banip
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
luci-app-banip versions 0 through 0.11.1
Description
A log parsing flaw exists where the
awk-based parser extracts the first IPv4 address from log lines regardless of its field position. This allows an unauthenticated remote attacker to inject an arbitrary IP address through attacker-controlled fields, such as the login username field. Consequently, the system may block an incorrect target while the actual attacker remains unblocked.Recommendations
Update luci-app-banip to a version later than 0.11.1.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luci-App-Banip