Description
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.
Published: 2026-05-26
Score: 8.7 High
EPSS: 6.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the setInitAction function of the luci-app-https-dns-proxy add‑on. An authenticated user who holds the luci.https-dns-proxy ACL permission can supply shell metacharacters through the 'name' parameter of a ubus RPC call, causing arbitrary command execution with root privileges on the device.

Affected Systems

Affected are installations of mossdef-org:luci-app-https-dns-proxy through version 2025.12.29‑5 on OpenWrt routers. The package is optional and not installed by default; only devices that have added the LuCI web package are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 marks high severity. The EPSS score of 7% indicates a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description does not state whether the ubus RPC interface is reachable externally, so remote exploitation is inferred rather than confirmed. If the interface is network‑reachable, the attack can be carried out remotely; otherwise it remains code execution locally.

Generated by OpenCVE AI on July 27, 2026 at 04:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official update for luci-app‑https‑dns‑proxy from the OpenWrt community package feed to eliminate the command injection flaw.
  • If the package is not needed for your service, uninstall or disable luci-app‑https‑dns‑proxy to remove the attack surface.
  • Restrict the luci.https-dns-proxy ACL so that only trusted local users have permission to invoke the setInitAction function.
  • Block external access to the LuCI web interface and ubus RPC endpoint with firewall rules, ensuring the interface is only reachable from trusted internal networks.

Generated by OpenCVE AI on July 27, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mossdef
Mossdef luci-app-https-dns-proxy
CPEs cpe:2.3:a:mossdef:luci-app-https-dns-proxy:*:*:*:*:*:*:*:*
Vendors & Products Mossdef
Mossdef luci-app-https-dns-proxy

Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Mossdef-org
Mossdef-org luci-app-https-dns-proxy
Vendors & Products Mossdef-org
Mossdef-org luci-app-https-dns-proxy

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.
Title luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mossdef Luci-app-https-dns-proxy
Mossdef-org Luci-app-https-dns-proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T21:32:56.384Z

Reserved: 2026-05-13T19:40:27.809Z

Link: CVE-2026-46368

cve-icon Vulnrichment

Updated: 2026-05-26T14:47:48.335Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T15:16:39.730

Modified: 2026-06-17T10:53:36.687

Link: CVE-2026-46368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T04:15:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')