PT-2026-82517 · Undefined · Undefined
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
luci-app-https-dns-proxy versions prior to 2026-01-17
Description
Authenticated users can execute arbitrary shell commands due to improper handling of shell metacharacters in the
name parameter within the setInitAction() function located in /usr/libexec/rpcd/luci.https-dns-proxy.Recommendations
Update luci-app-https-dns-proxy to a version released on or after 2026-01-17.
As a temporary mitigation, restrict access to the
setInitAction() function to prevent unauthorized command execution.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined