Impact
The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy accepts a name parameter from authenticated users and passes it directly to a shell without sanitization. This allows injection of shell metacharacters, leading to arbitrary command execution on the router, potentially compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects any OpenWrt device that includes the luci-app-https-dns-proxy package prior to the merge of pull request “#15” on January 17 2026. Systems where authenticated users can access the luci.https-dns-proxy endpoint through setInitAction are impacted.
Risk and Exploitability
An attacker must have valid credentials to access the LUCI interface but otherwise can inject commands and obtain full root privileges on the device. The CVSS score of 8.8 indicates high severity, while an EPSS score of <1% suggests a low current exploitation rate. The vulnerability is not listed in the CISA KEV catalog. Should exploitation occur, the attacker would gain complete control over the router.
OpenCVE Enrichment