Impact
The vulnerability is a command injection flaw in the setInitAction function of the luci-app-https-dns-proxy add‑on. An authenticated user who holds the luci.https-dns-proxy ACL permission can supply shell metacharacters through the 'name' parameter of a ubus RPC call, causing arbitrary command execution with root privileges on the device.
Affected Systems
Affected are installations of mossdef-org:luci-app-https-dns-proxy through version 2025.12.29‑5 on OpenWrt routers. The package is optional and not installed by default; only devices that have added the LuCI web package are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 marks high severity. The EPSS score of 7% indicates a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description does not state whether the ubus RPC interface is reachable externally, so remote exploitation is inferred rather than confirmed. If the interface is network‑reachable, the attack can be carried out remotely; otherwise it remains code execution locally.
OpenCVE Enrichment