Impact
The vulnerability allows an authenticated user with luci.https-dns‑proxy ACL permission to inject shell metacharacters through the 'name' parameter of an ubus RPC call to the setInitAction function in luci-app-https-dns‑proxy. This results in arbitrary command execution as root, compromising confidentiality, integrity, and availability. The flaw is a command‑injection weakness categorized as CWE‑77.
Affected Systems
lucI-app‑https‑dns‑proxy versions through 2025.12.29‑5 and earlier on OpenWrt devices that have installed the add‑on. Only installations that include this optional LuCI web UI component are vulnerable; the core OpenWrt system is not affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability with significant impact. EPSS is not provided, and the vulnerability is not listed in CISA KEV. The attack requires authentication and the appropriate ACL, implying that an attacker must already have valid credentials or access to the LuCI interface or ubus RPC. Once authenticated, exploitation can be performed remotely via web UI or RPC calls, making the risk moderate to high for affected devices.
OpenCVE Enrichment