CVE 8.7 HIGH

luci-app-https-dns-proxy Authenticated Command Injection via setInitAction_CVE-2026-46368

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.

AI Analysis

Command injection vulnerability in luci-app-https-dns-proxy allowing arbitrary command execution as root

Basic Information

ID CVE-2026-46368
Source VulnCheck
Published May 26, 2026 at 14:08
Modified May 26, 2026 at 14:47

Affected Product

Vendor mossdef-org
Product luci-app-https-dns-proxy
Affected Versions mossdef-org luci-app-https-dns-proxy 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor OpenWrt
Product luci-app-https-dns-proxy
Version through 2025.12.29-5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.